Neueste VersionenFixList
11.1.0.7 FixList
10.5.0.9 FixList
10.1.0.6 FixList
9.8.0.5 FixList
9.7.0.11 FixList
9.5.0.10 FixList
9.1.0.12 FixList
Haben Sie Probleme? - Kontaktieren Sie uns.
Kostenlos registrieren anmeldung-x26
Kontaktformular kontakt-x26

DB2 - Problembeschreibung

Problem IC68762 Status: Geschlossen

SECURITY: THE TIVOLI MONITORING AGENT (KUDDB2) FOR DB2 HAS DOS
VULNERABILITY. (CVE-2010-0472)

Produkt:
DB2 FOR LUW / DB2FORLUW / 970 - DB2
Problembeschreibung:
The Tivoli Monitoring Agent (kuddb2) for DB2 has a remote Denial 
of Service vulnerability which would prevent IBM Data Studio 
Administration Console (DSAC) from monitoring DB2.  The DB2 
server is unaffected by this vulnerability.
Problem-Zusammenfassung:
**************************************************************** 
* USERS AFFECTED:                                              * 
* All DB2 systems using DB2 Data Studio Administrative Console * 
* on all Linux, Unix and Windows platforms at service levels   * 
* Version 9.7 GA.                                              * 
**************************************************************** 
* PROBLEM DESCRIPTION:                                         * 
* See Error Description                                        * 
**************************************************************** 
* RECOMMENDATION:                                              * 
* ************************************************************ * 
* ****                                                         * 
*     * RECOMMENDATION:                                        * 
* *                                                            * 
*     * The fix as described in the "Local Fix" section of the * 
* APAR  *                                                      * 
*     * is sufficient to mitigate the vulnerability.           * 
* *                                                            * 
*                                                              * 
* ************************************************************ * 
* ****                                                         * 
*                                                              * 
* Problem conclusion                                           * 
*                                                              * 
*     The fix as described in the "Local Fix" section of the   * 
* APAR is sufficient to mitigate the vulnerability..           * 
****************************************************************
Local-Fix:
The workaround is to configure the Tivoli Monitoring Agent 
(kuddb2) to use ephemeral ports which will make the agent 
invisible to outsiders. 
 
To enable ephemeral ports, change the original KDC_FAMILIES 
entry in kincms.ini to "KDC_FAMILIES=EPHEMERAL:Y IP.PIPE 
IP.SPIPE SNA IP HTTP_CONSOLE:N HTTP_SERVER:N". 
 
This needs to be done at for each DB2 server instance. 
 
 
Each DB2 server instance has its own ini file.  The ini file 
name format is as follows: 
<DB2_Install_Path>/itma/TMAITM6/kudcma_<INSTANCE_NAME>.ini 
 
You will need to restart the IBM Data Studio Administration 
Console Monitoring server/service and the Tivoli Monitoring 
Agent.
verfügbare FixPacks:
DB2 Version 9.7 Fix Pack 2 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 3 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 3a for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 4 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 5 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 6 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 7 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 9a for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 8 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 9 for Linux, UNIX, and Windows
DB2 Version 9.7 Fix Pack 10 for Linux, UNIX, and Windows

Lösung
Workaround
keiner bekannt / siehe Local-Fix
Weitere Daten
Datum - Problem gemeldet    :
Datum - Problem geschlossen :
Datum - der letzten Änderung:
20.05.2010
03.04.2013
03.04.2013
Problem behoben ab folgender Versionen (IBM BugInfos)
Problem behoben lt. FixList in der Version
9.7.0.2 FixList