IBM Support

JR29274: SECURITY: MALICIOUS PACKETS SENT TO DB2JDS CAUSES CRASH.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Malicious packets sent to db2jds will cause db2jds to crash.
    db2jds is the IBM DB2 JDBC Applet Server Service.
    This problem was reported to IBM by Ariel Sanchez of
    ApplicationSecurity Inc.
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    ALL
    ****************************************************************
    PROBLEM DESCRIPTION:
    Malicious packets sent to db2jds will cause db2jds to crash.
    db2jds is the IBM DB2 JDBC Applet Server Service.
    ****************************************************************
    RECOMMENDATION:
    Upgrade to V8.2 FP17.
    ****************************************************************
    

Problem conclusion

  • First fixed in DB2 UDB Version v8.2, FixPak 17
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR29274

  • Reported component name

    DB2 CEE WINDOWS

  • Reported component ID

    5765F3001

  • Reported release

    820

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2008-05-13

  • Closed date

    2008-09-04

  • Last modified date

    2008-09-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    JR29935 JR29936

Fix information

  • Fixed component name

    DB2 CEE WINDOWS

  • Fixed component ID

    5765F3001

Applicable component levels

  • R910 PSY

       UP

  • R950 PSY

       UP

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSEPGG","label":"Db2 for Linux, UNIX and Windows"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"820","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
04 September 2008