CVE-2014-6159
Description
IBM DB2 with immediate AUTO_REVAL allows authenticated users to crash the server via a crafted ALTER TABLE statement.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM DB2 with immediate AUTO_REVAL allows authenticated users to crash the server via a crafted ALTER TABLE statement.
Vulnerability
IBM DB2 on Linux, UNIX, and Windows contains a denial-of-service vulnerability in the handling of ALTER TABLE statements when the AUTO_REVAL configuration parameter is set to IMMEDIATE (the default is DEFERRED). A remote authenticated user with control privileges on a target table can execute a specially crafted ALTER TABLE statement, causing the DB2 server to terminate abnormally. Affected versions include DB2 9.7 before Fix Pack 10 (FP10), 9.8 through Fix Pack 5 (FP5), 10.1 through Fix Pack 4 (FT4), and 10.5 through Fix Pack 4 (FP4). The vulnerability also affects the IBM DB2 component used in InfoSphere BigInsights Big SQL [1][2].
Exploitation
To exploit this vulnerability, an attacker must have valid security credentials to connect to the database and must possess control privileges on the target table. The attacker then sends a crafted ALTER TABLE statement over the network. No additional user interaction is required. The attack complexity is medium, as the attacker needs to craft the statement appropriately [1].
Impact
Successful exploitation results in a denial of service: the DB2 server crashes and must be restarted. There is no impact on data confidentiality or integrity. The CVSS v2 base score is 6.3 (AV:N/AC:M/Au:S/C:N/I:N/A:C) [1].
Mitigation
IBM has released fixes for the affected versions: DB2 9.7 FP10, 10.1 FT5, and 10.5 FP5. For InfoSphere BigInsights, apply the corresponding DB2 fix pack. As a workaround, administrators can set the AUTO_REVAL parameter to DEFERRED (the default) to avoid the vulnerable code path. No known exploitation in the wild or KEV listing has been reported [1][2].
- IBM® DB2® LUW contains a vulnerability in which an ALTER TABLE statement may cause the DB2 server to terminate abnormally when AUTO_REVAL is set to IMMEDIATE . (CVE-2014-6159)
- Security Bulletin: Infosphere BigInsights contains multiple vulnerabilities in which an ALTER TABLE statement may cause the Big SQL server to terminate abnormally. (CVE-2014-6159, CVE-2014-6209, CVE-2014-6210)
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- www-01.ibm.com/support/docview.wssnvdVendor Advisory
- secunia.com/advisories/62092nvd
- secunia.com/advisories/62093nvd
- www-01.ibm.com/support/docview.wssnvd
- www-01.ibm.com/support/docview.wssnvd
- www-01.ibm.com/support/docview.wssnvd
- www-01.ibm.com/support/docview.wssnvd
- www.securityfocus.com/bid/71006nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/97708nvd
News mentions
0No linked articles in our index yet.