Application Security Inc. - Database Security, Monitoring, Assessment, Auditing, Encryption, and Regulatory Compliance.
 
 
 
home client login partner login purchasing info contact us
search:
Solutions Products Partners Support News & Events About Us

Team SHATTER Security Advisory

Multiple DoS vulnerabilities in SQLJRA protocol

March 11, 2008

Risk Level:
High

Affected versions:
DB2 versions 8.1,8.2,9.1

Remote exploitable:
Yes

Credits:
These vulnerabilities were discovered and researched by Martin Rakhmanov, Cesar Cerrudo and Esteban Martinez Fayo of Application Security Inc.

Details:
Multiple Denial of Service vulnerabilities exist in DB2.
A specially crafted SQLJRA packet can cause the DB2 instance to crash.
No special privileges are required to exploit these vulnerabilities.

Impact:
Any remote unauthenticated attacker can crash the DB2 instance.

Vendor Status:
Vendor was contacted and a patch was released.

Fix:
To fix the problem apply the fixpak 16 for DB2 versions 8.1/8.2 and fixpack 4a for DB2 version 9.1
http://www-1.ibm.com/support/docview.wss?rs=71&uid=swg21256235
http://www-1.ibm.com/support/docview.wss?rs=71&uid=swg21255572

APAR:
IZ05043
IZ07299

Links:
Application Security, Inc advisory: http://www.appsecinc.com/resources/alerts/db2/2008-01.shtml
IBM APAR: http://www-1.ibm.com/support/docview.wss?rs=71&uid=swg21255352#r16
http://www-1.ibm.com/support/docview.wss?rs=71&uid=swg21255607#r4a


_____________________________________________
Copyright © 2008 Application Security, Inc.
http://www.appsecinc.com


Application Security, Inc’s database security solutions have helped over 900 organizations secure their databases from all internal and external threats
while also ensuring that those organizations meet or exceed regulatory compliance and audit requirements.


Disclaimer: The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.