Vulnerabilities > CVE-2012-0712 - Resource Management Errors vulnerability in IBM DB2 9.5/9.7/9.8

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
ibm
CWE-399
nessus

Summary

The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.

Vulnerable Configurations

Part Description Count
Application
Ibm
24

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDatabases
    NASL idDB2_98FP5.NASL
    descriptionAccording to its version, the installation of IBM DB2 9.8 running on the remote host is prior to Fix Pack 5. It is, therefore, affected by multiple vulnerabilities : - An authorized user with
    last seen2020-06-01
    modified2020-06-02
    plugin id59905
    published2012-07-10
    reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/59905
    titleIBM DB2 9.8 < Fix Pack 5 Multiple Vulnerabilities
  • NASL familyDatabases
    NASL idDB2_95FP9.NASL
    descriptionAccording to its version, the installation of IBM DB2 9.5 running on the remote host is prior to Fix Pack 9. It is, therefore, affected by the following vulnerabilities : - Incorrect, world-writable file permissions are in place for the file
    last seen2020-06-01
    modified2020-06-02
    plugin id58293
    published2012-03-08
    reporterThis script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/58293
    titleDB2 9.5 < Fix Pack 9 Multiple Vulnerabilities
  • NASL familyDatabases
    NASL idDB2_97FP6.NASL
    descriptionAccording to its version, the installation of DB2 9.7 running on the remote host is prior to Fix Pack 6. It is, therefore, affected by multiple vulnerabilities : - A local user can exploit a vulnerability in the bundled IBM Tivoli Monitoring Agent (ITMA) to escalate their privileges. (CVE-2011-4061) - An authorized user with
    last seen2020-06-01
    modified2020-06-02
    plugin id59904
    published2012-07-10
    reporterThis script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/59904
    titleIBM DB2 9.7 < Fix Pack 6 Multiple Vulnerabilities

Oval

accepted2013-07-29T04:00:10.161-04:00
classvulnerability
contributors
  • nameScott Quint
    organizationDTCC
  • nameMaria Kedovskaya
    organizationALTX-SOFT
definition_extensions
commentIBM DB2 UDB is installed
ovaloval:org.mitre.oval:def:12505
descriptionThe XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
familywindows
idoval:org.mitre.oval:def:14450
statusaccepted
submitted2012-03-26T11:21:44.000-05:00
titleThe XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPARSE function with a crafted string expression.
version7