DB2 - Problem description
Problem IC81462 | Status: Closed |
SECURITY: UNAUTHORIZED ACCESS TO XML FILES IN DB2'S XML FEATURE (CVE-2012-0713). | |
product: | |
DB2 FOR LUW / DB2FORLUW / 970 - DB2 | |
Problem description: | |
There is a security vulnerability in the DB2's XML Feature which would allow an authenticated, malicious user to remotely gain access to XML files owned by the instance owner. To exploit the vulnerability, the user would need to have valid security credentials, and CONNECT privilege to the database. | |
Problem Summary: | |
**************************************************************** * USERS AFFECTED: * * All DB2 systems on all Linux, Unix and Windows platforms at * * service levels Version 9.7 GA through to Version 9.7 Fix * * Pack 5. * **************************************************************** * PROBLEM DESCRIPTION: * * See Error Description * **************************************************************** * RECOMMENDATION: * * Upgrade to DB2 Version 9.7 Fix Pack 6 or see "Local Fix" * * portion for other suggestions. * **************************************************************** | |
Local Fix: | |
The vulnerability could be mitigated by revoking CONNECT privilege from public. | |
available fix packs: | |
DB2 Version 9.7 Fix Pack 6 for Linux, UNIX, and Windows | |
Solution | |
The complete fix for this problem first appears in DB2 Version 9.7 Fix Pack 6 and all the subsequent Fix Packs. | |
Workaround | |
not known / see Local fix | |
Timestamps | |
Date - problem reported : Date - problem closed : Date - last modified : | 15.02.2012 31.05.2012 11.06.2012 |
Problem solved at the following versions (IBM BugInfos) | |
9.7.FP6 | |
Problem solved according to the fixlist(s) of the following version(s) | |
9.7.0.6 |