VYPR
Unrated severityNVD Advisory· Published Oct 5, 2010· Updated Jun 16, 2026

CVE-2010-3731

CVE-2010-3731

Description

Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • IBM/Db211 versions
    cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:ibm:db2:9.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp1:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp2:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp2a:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp3:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp3a:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp3b:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp4:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp4a:*:*:*:*:*:*
    • cpe:2.3:a:ibm:db2:9.5:fp5:*:*:*:*:*:*
    • (no CPE)range: >=9.1, <FP10 || >=9.5, <FP6a || >=9.7, <FP3

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.