IBM DB2 Universal Database Information Disclosure Vulnerability

The following attacks were published:

- Database usernames and passwords may be read from the 'DB2SHMSECURITYSERVICE' memory section.

- Various shared memory sections may be read allowing unauthorized access to query or query result data. The following examples were provided:

section read DB20QM
section read DB2GLBQ0QM
section read DB2SHMDB2_0APP
section read DB2SHMDB2_0APL00000003
section read DB2SHMDB2_0APL00000004
section read DB2SHMDB2_0APL00000005


 

Privacy Statement
Copyright 2010, SecurityFocus