IBM issues updates to fix serious DB2 flaws

Article

IBM issues updates to fix serious DB2 flaws

IBM released an update Wednesday to patch at least 10 vulnerabilities in its DB2 database management system (DBMS).

The IBM Fix Packs address flaws in DB2 versions 9.1, 9.5 and DB2 Universal Database versions 8.1 and 8.2. The

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

DBMS is affected by SQL injection vulnerabilities, an error that could result in password disclosure and a flaw that could reveal sensitive data.

Danish vulnerability clearinghouse Secunia gave the flaws a "moderately critical" rating and warned that the flaws could be exploited remotely.

"Some have an unknown impact and others can be exploited by malicious people to cause a DoS (denial of service) and disclose potentially sensitive information," Secunia said in its advisory.

The French Security Incident Response Team (FrSIRT) posted advisories for the latest DB2 vulnerabilities on its website. It also gave the flaws a "moderate risk" rating.