NOTE: Due to permission issues the vendor does not recommend to install Fixpak 15 or 16 for DB Universal Database 8 on Solaris platforms. Please see the vendor advisory for more information. http://www-1.ibm.com/support/docview.wss?uid=swg21295375
Provided and/or discovered by: 1) Joshua J. Drake, iDefense Labs
2) Discovered by an anonymous person and reported via iDefense Labs.
3) Discovered independently by:
* Joshua J. Drake, iDefense Labs
* An anonymous person, reported via iDefense Labs.
4) Discovered by an anonymous person and reported via iDefense Labs.
5) Discovered by an anonymous person and reported via iDefense Labs.
6) Discovered by an anonymous person and reported via iDefense Labs.
7) Ariel Sanchez, Application Security Inc.
8)-13) Reported by the vendor.
Changelog: 2007-08-17: Updated additional information and links from iDefense Labs and IBM. Added CVE references.
2007-08-22: Added CVE reference.
2007-09-04: Updated advisory with additional "System Access" impact and additional information from Application Security Inc. Added additional links to IBM and Application Security Inc.
2007-10-26: Added additional IBM link.
2008-04-10: Added note to "Solution" section about issues with Fixpak 15 and 16 for DB2 Universal Database 8.
2008-07-11: Added vulnerability #13 and link to vendor advisory.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.