VYPR
Unrated severityNVD Advisory· Published Jun 3, 2009· Updated Jun 16, 2026

CVE-2008-2154

CVE-2008-2154

Description

IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.

Affected products

16
  • IBM/Db216 versions
    cpe:2.3:a:ibm:db2:8.0:fp1:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:ibm:db2:8.0:fp1:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp10:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp11:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp12:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp13:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp14:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp15:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:8.0:fp16:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp1:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp2:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp3:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp3a:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp4:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.1:fp4a:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp1:*:*:*:*:*:*
    • (no CPE)range: < FP17 (v8), < FP5 (v9.1), < FP2 (v9.5)

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.