← Vulnerability feed

Vulnerability record · CVE-2008-0699 · published 12 February 2008

CVE-2008-0699: Ibm db2 vulnerability

Ibm · Db2

Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.

9.0 CVSS 2.0 High EPSS 5.2% · top 7.8%
9.0CVSS 2.0 base score
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT Vendor Advisory
http://osvdb.org/41795 Broken Link
http://secunia.com/advisories/28771 Third Party Advisory
http://secunia.com/advisories/29022 Third Party Advisory
http://secunia.com/advisories/29784 Third Party Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06972 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06973 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10917 PatchVendor Advisory
http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml Third Party Advisory
http://www.securityfocus.com/archive/1/491075/100/0/threaded Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2008/0401 Third Party Advisory
ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT Vendor Advisory
http://osvdb.org/41795 Broken Link
http://secunia.com/advisories/28771 Third Party Advisory
http://secunia.com/advisories/29022 Third Party Advisory
http://secunia.com/advisories/29784 Third Party Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06972 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ06973 PatchVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ10917 PatchVendor Advisory
http://www.appsecinc.com/resources/alerts/db2/2008-02.shtml Third Party Advisory
http://www.securityfocus.com/archive/1/491075/100/0/threaded Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2008/0401 Third Party Advisory

Track CVE-2008-0699 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-1797Ibm db2 permissions and access controls vulnerabilityIBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.EPSS 1.7%10.0CVE-2010-3731Ibm db2 memory buffer overflow vulnerabilityStack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration …EPSS 9.6%10.0CVE-2010-3193Ibm db2 vulnerabilityUnspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.EPSS 2.7%10.0CVE-2009-4335Ibm db2 vulnerabilityMultiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and…EPSS 2.3%10.0CVE-2009-3473Ibm db2 vulnerabilityIBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and re…EPSS 2.0%10.0CVE-2008-6820Ibm db2 vulnerabilityThe db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and att…EPSS 1.8%10.0CVE-2008-6821Ibm db2 memory buffer overflow vulnerabilityBuffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cau…EPSS 3.7%10.0CVE-2008-4692Ibm db2 vulnerabilityThe Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, …EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2008-0699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.