CVE-2015-1935

high
Published 2015-07-20 · Modified 2026-05-06
CVSS v3
CVSS v2
8.0
VIR risk
8.0

Description

The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21902661

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IT08543

Application impact

VendorProductVersionsFixed
ibmdb29.7
ibmdb29.8
ibmdb210.1
ibmdb210.5

References

CWEs

CWE-17

Verify integrity in audit chain (admin only). AS-IS.