>> IBM DB2 Universal Database JDBC Applet Server Remote Code Execution Vulnerability
Title : IBM DB2 Universal Database JDBC Applet Server Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-1707 CVE ID : CVE-2007-2582
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-08
Technical Description
A vulnerability has been identified in IBM DB2 Universal Database, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the DB2 JDBC Applet Server (DB2JDS) service when processing malformed requests sent to port 6789/TCP, which could be exploited by remote attackers to crash an affected service or execute arbitrary code with elevated privileges.
Note : Two other vulnerabilities exist within the handling of malformed packets, which could be exploited by atackers to cause a denial of service.