CVE-2002-1583

IBM DB2 Universal Database <7.0 - RCE

Title source: llm
STIX 2.1

Description

Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.

References (3)

Core 3
Core References
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4817
Patch, Vendor Advisory vendor-advisory x_refsource_ibm
http://www.securitytracker.com/alerts/2002/May/1004352.html
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9078.php

Scores

EPSS 0.0047
EPSS Percentile 38.4%

Details

Status published
Products (5)
ibm/db2_universal_database 6.0
ibm/db2_universal_database 7.0
ibm/db2_universal_database 7.1
ibm/db2_universal_database 7.2
ibm/db2_universal_database 8.2
Published Sep 28, 2004
Tracked Since Feb 18, 2026