CVE-2013-3031

low
Published 2013-09-09 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

A SQL stored procedure in the Universal Cache component in IBM solidDB 6.0.x before 6.0.1070, 6.3.x before 6.3.0.56, 6.5.x before 6.5.0.12, and 7.0.x before 7.0.0.4 allows remote authenticated users to cause a denial of service (uninitialized-memory access and daemon crash) via a call that includes named arguments and default parameter values, but does not include all of the expected arguments.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21643599

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IC94044

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IC94043

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IC88796

Application impact

VendorProductVersionsFixed
ibmsoliddb6.0
ibmsoliddb6.0.1060
ibmsoliddb6.0.1061
ibmsoliddb6.0.1064
ibmsoliddb6.0.1065
ibmsoliddb6.0.1066
ibmsoliddb6.0.1067
ibmsoliddb6.0.1068
ibmsoliddb6.0.1069
ibmsoliddb6.3.33
ibmsoliddb6.3.34
ibmsoliddb6.3.37
ibmsoliddb6.3.38
ibmsoliddb6.3.39
ibmsoliddb6.3.40
ibmsoliddb6.3.41
ibmsoliddb6.3.42
ibmsoliddb6.3.44
ibmsoliddb6.3.47
ibmsoliddb6.3.48
ibmsoliddb6.3.49
ibmsoliddb6.3.52
ibmsoliddb6.3.53
ibmsoliddb6.3.54
ibmsoliddb6.3.55
ibmsoliddb6.5.0.0
ibmsoliddb6.5.0.1
ibmsoliddb6.5.0.2
ibmsoliddb6.5.0.3
ibmsoliddb6.5.0.4
ibmsoliddb6.5.0.5
ibmsoliddb6.5.0.6
ibmsoliddb6.5.0.7
ibmsoliddb6.5.0.8
ibmsoliddb6.5.09
ibmsoliddb6.5.10
ibmsoliddb6.5.11
ibmsoliddb7.0.0.0
ibmsoliddb7.0.0.1
ibmsoliddb7.0.0.2
ibmsoliddb7.0.0.3

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.