CVE-2014-6159 — Improper Input Validation in IBM DB2

Severity
3.5LOWNVD
EPSS
1.1%
top 21.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 8
Latest updateMay 17

Description

IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

â–¶NVDibm/db24 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-464r-rw5h-5w5r: IBM DB2 9↗2022-05-17
â–¶
CVEList
CVE-2014-6159: IBM DB2 9↗2014-11-08
â–¶
CVE-2014-6159 — Improper Input Validation in IBM DB2 | cvebase