CVE-2012-2194
Publication date 25 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| db2exc | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
Notes
References
Other references
- http://www-01.ibm.com/support/docview.wss?uid=swg21600837
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC84716
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC84715
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC84714
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC84711
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC84019
- https://www.cve.org/CVERecord?id=CVE-2012-2194