CVE-2008-0699

IBM DB2 UDB - Authenticated Remote Code Execution via ADMIN_SP_C Procedure

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.

References (11)

Core 11
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/491075/100/0/threaded
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06972
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06973
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10917
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28771
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0401
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29784
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29022
Third Party Advisory x_refsource_misc
http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/41795

Scores

EPSS 0.0520
EPSS Percentile 91.6%

Details

Status published
Products (3)
ibm/db2 8.2 fp1 (16 CPE variants)
ibm/db2 9.1 (7 CPE variants)
ibm/db2 9.5
Published Feb 12, 2008
Tracked Since Feb 18, 2026