IBM Support

Security Bulletin: BigInsights is affected by a vulnerability in DB2 (CVE-2014-0919, CVE-2016-0211)

Security Bulletin


Summary

BigInsights is affected by a vulnerability in DB2 (CVE-2014-0919, CVE-2016-0211).

Vulnerability Details


CVEID: CVE-2016-0211
DESCRIPTION:
IBM DB2 LUW contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted DRDA message and cause DB2 server to terminate abnormally.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/109608 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2014-0919
DESCRIPTION:
IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/91981
for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS: 4.0/AV:N/AC:L/Au:S/C:P/I:N/A:N)

Affected Products and Versions

IBM InfoSphere BigInsights: 3.0.0.2, 4.0, 4.1

Remediation/Fixes

Principal Product and Version(s)

Fix
IBM InfoSphere BigInsights 4.xApply rpm from Fix Central: db2luw_4_1_0_2-10.6-0.3x86_64rhel6.rpm
IBM InfoSphere BigInsights: 3.0.0.2 Apply IFix from Fix Central:
IM-BigInsights-EE-linuxamd64_DB2_malformatted_DRDA_messages

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

31 August 2016: Original Version Published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSCRJT","label":"IBM Db2 Big SQL"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Big SQL","Platform":[{"code":"PF016","label":"Linux"}],"Version":"3.0.0.2;4.0.0;4.1.0","Edition":"Enterprise Edition","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
18 July 2020

UID

swg21987604