CVE-2015-1935
IBM DB2 9.7-10.5 - Remote Code Execution or Denial of Service
Title source: llmDescription
The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75908
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT08543
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21902661
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033063
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT08656
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT08668
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT08667
Scores
EPSS
0.0352
EPSS Percentile
88.0%
Details
CWE
CWE-17
Status
published
Products (4)
ibm/db2
9.7 (5 CPE variants)
ibm/db2
9.8 (5 CPE variants)
ibm/db2
10.1 (5 CPE variants)
ibm/db2
10.5 (5 CPE variants)
Published
Jul 20, 2015
Tracked Since
Feb 18, 2026