CVE-2015-0157

medium
Published 2015-07-20 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21697987

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IT07108

Application impact

VendorProductVersionsFixed
ibm ibmdb29.7
ibm ibmdb29.8
ibm ibmdb210.1
ibm ibmdb210.5

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.