Vulnerable Systems:
* IBM DB2 LUW 9.1, 9.5, 9.7, 10.1
Two system stored procedures executable by PUBLIC allow reading files with xml extension on the server. To exploit this vulnerability the xml file should be readable by the DB2 fenced user.
Impact:
Authenticated database users can read xml files accessible to the DB2 fenced process.
Workaround:
Revoke EXECUTE privilege on GET_WRAP_CFG_C and GET_WRAP_CFG_C2 system stored procedures from PUBLIC.
Fix:
IBM DB2 LUW 9.1: apply Fix Pack 12.
IBM DB2 LUW 9.5: apply Fix Pack 10.
IBM DB2 LUW 9.7: no fix yet.
IBM DB2 LUW 10.1: apply Fix Pack 1.