IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
2018-01-16T19:29:00.887
2024-11-21T02:41:17.433
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 9.7 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.1 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Application | ibm | db2 | 10.5 | Yes |
Operating System | hp | hp-ux | - | No |
Operating System | ibm | aix | - | No |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |
Operating System | oracle | solaris | - | No |
Application | ibm | db2 | 9.8 | Yes |
Operating System | ibm | aix | - | No |
Operating System | linux | linux_kernel | - | No |