Vulnerability Name:

CCN-17609

Published:2004-10-06
Updated:2004-10-06
Summary:IBM DB2 Universal Database is vulnerable to a denial of service attack. A remote authenticated attacker could signal the DB2 UDB instance to close.
CVSS v3 Severity:3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: VulnWatch Mailing List, Wed Sep 01 2004 - 11:45:33 CDT
Patch available for IBM DB2 Universal Database flaws

Source: CCN
Type: VulnWatch] Mailing List, Tue Oct 05 2004 - 09:15:52 CDT
Patch available for critical IBM DB2 Universal Database flaws

Source: CCN
Type: IBM APAR IY62305
USERS CAN SIGNAL THE SEMAPHORE USED TO SHUT DOWN THE DB2 UDB INSTANCE.

Source: CCN
Type: IBM TechNote 1181228
APARs included in DB2 UDB Version 8 FixPak 6a and FixPak 7a

Source: CCN
Type: IBM DB2 version 7 FixPaks Download Web page
DB2 Universal Datavase for Linux, UNIX and Windows

Source: CCN
Type: IBM DB2 version 8 FixPaks Download Web page
DB2 Universal Datavase for Linux, UNIX and Windows

Source: CCN
Type: BID-11327
IBM DB2 Multiple Critical Remote Vulnerabilities

Source: CCN
Type: BID-11403
IBM DB2 Semaphore Signaling Denial Of Service Vulnerability

Source: XF
Type: UNKNOWN
db2-signal-instance-dos(17609)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:ibm:db2_universal_database:7.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.0:fp14:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.0:fp13:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.6c:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.7b:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.8a:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.1.9a:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.10:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.12:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:db2_universal_database:8.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm db2 universal database 7.1
    ibm db2 universal database 7.0
    ibm db2 universal database 8.1
    ibm db2 universal database 7.2
    ibm db2 universal database 8.0
    ibm db2 universal database 8.0 fp14
    ibm db2 universal database 8.0 fp13
    ibm db2 universal database 8.1.4
    ibm db2 universal database 8.1.5
    ibm db2 universal database 8.1.6
    ibm db2 universal database 8.1.6c
    ibm db2 universal database 8.1.7
    ibm db2 universal database 8.1.7b
    ibm db2 universal database 8.1.8
    ibm db2 universal database 8.1.8a
    ibm db2 universal database 8.1.9
    ibm db2 universal database 8.1.9a
    ibm db2 universal database 8.10
    ibm db2 universal database 8.12
    ibm db2 universal database 8.2