DB2 - Problembeschreibung
Problem IC81462 | Status: Geschlossen |
SECURITY: UNAUTHORIZED ACCESS TO XML FILES IN DB2'S XML FEATURE (CVE-2012-0713). | |
Produkt: | |
DB2 FOR LUW / DB2FORLUW / 970 - DB2 | |
Problembeschreibung: | |
There is a security vulnerability in the DB2's XML Feature which would allow an authenticated, malicious user to remotely gain access to XML files owned by the instance owner. To exploit the vulnerability, the user would need to have valid security credentials, and CONNECT privilege to the database. | |
Problem-Zusammenfassung: | |
**************************************************************** * USERS AFFECTED: * * All DB2 systems on all Linux, Unix and Windows platforms at * * service levels Version 9.7 GA through to Version 9.7 Fix * * Pack 5. * **************************************************************** * PROBLEM DESCRIPTION: * * See Error Description * **************************************************************** * RECOMMENDATION: * * Upgrade to DB2 Version 9.7 Fix Pack 6 or see "Local Fix" * * portion for other suggestions. * **************************************************************** | |
Local-Fix: | |
The vulnerability could be mitigated by revoking CONNECT privilege from public. | |
verfügbare FixPacks: | |
DB2 Version 9.7 Fix Pack 6 for Linux, UNIX, and Windows | |
Lösung | |
The complete fix for this problem first appears in DB2 Version 9.7 Fix Pack 6 and all the subsequent Fix Packs. | |
Workaround | |
keiner bekannt / siehe Local-Fix | |
Weitere Daten | |
Datum - Problem gemeldet : Datum - Problem geschlossen : Datum - der letzten Änderung: | 15.02.2012 31.05.2012 11.06.2012 |
Problem behoben ab folgender Versionen (IBM BugInfos) | |
9.7.FP6 | |
Problem behoben lt. FixList in der Version | |
9.7.0.6 |