Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-2154
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-2154

Description:
IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/51105

SAID
  Secunia Advisory: SA31787

OSVDB
  48147

CONFIRM
  http://www-01.ibm.com/support/docview.wss?uid=swg21318189

BID
  35409

AIXAPAR
  http://www-01.ibm.com/support/docview.wss?uid=swg1IZ22143
  http://www-01.ibm.com/support/docview.wss?uid=swg1IZ22142
  http://www-01.ibm.com/support/docview.wss?uid=swg1IZ21983


Return to the previous page.