Business Services Industry
Imperva Discovers Critical Denial of Service Vulnerability in IBM DB2 Database; Application Defense Center Identifies Disturbing Trend in Database Communications Protocol Flaws
Business Wire, Sept 6, 2006
Imperva--
Related Results
WHO: Imperva Application Defense Center (ADC)
WHAT: Discovered and reported to IBM a severe vulnerability in the
implementation of DB2 version 8's client-server protocol
called DRDA, which is used to exchange information and
commands between clients and servers. By exploiting the flaw,
any attacker with basic access credentials to the database
server can take it down. Since this is a database
communication protocol level vulnerability, attacks elude
DB2's built-in auditing mechanism. Database communications
protocol vulnerabilities are on the rise. In the two most
recent FixPaks issued by IBM, four of the seven security flaws
fixed have been protocol level holes. Meanwhile, half of the
vulnerabilities addressed in the latest Oracle quarterly patch
were protocol flaws. For more details on why these database
communications protocol vulnerabilities are increasing see the
Imperva Security Advisory listed below.
WHERE: The Imperva Security Advisory is available at:
http://www.imperva.com/application_defense_center/papers/ibm-dbms-0905
2006.html (Due to its length, this URL may need to be copied/pasted
into your Internet browser's address field. Remove the extra space if
one exists.)
IBM DB2 UDB Version 8.1 FixPak 13, as well as the Authorized
Program Analysis Report (APAR) which lists this and all
software defects in FixPak 13, are located at:
http://www-1.ibm.com/support/docview.wss?uid=swg24013114
WHEN: IBM released APAR IY87211 on August 14, 2006.
HOW: ADC conducts ongoing research into database security issues,
and discovered this vulnerability as part of its inspection of
database access protocols. ADC's research findings are applied
immediately, and in advance of vendor fixes, to enhance the
SecureSphere product line with next generation attack
detection and protection features for its customers worldwide.
About Imperva
Imperva is the leader in data security for the data center. The award-winning SecureSphere product line provides data security, auditing, and regulatory compliance for sensitive financial and identity data in corporate data centers. SecureSphere monitors and audits database activity as well as protects databases against insider abuse and external data theft via web applications. Deployment requires no changes to existing infrastructure and no manual tuning. Imperva SecureSphere is deployed in leading financial, healthcare, and retail organizations around the globe. Led by Shlomo Kramer, a Check Point Software Technologies founder, Imperva is privately funded by Accel Partners, Greylock Partners, US Venture Partners, and Venrock Associates.
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- Fox Networks Group and Bright House Networks Strike Comprehensive Deal to Distribute Fox Broadcast Stations, National Cable and Regional Sports Networks
- Fox Networks Group and Time Warner Cable Strike Comprehensive Deal to Distribute Fox Broadcast Stations, National Cable and Regional Sports Networks
- Houston Radio D.J. Kevin Kline Completes 500-Mile, 13-Day Ultramarathon Across Texas for Kids with Cancer
- Seaspan Corporation Provides Information on the CSCL Hamburg
- Dodecylamine improves nanocrystal synthesis
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- LIFO vs. FIFO: a return to the basics
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- Using object-oriented analysis and design over traditional structured analysis and design
- Design a commission plan that drives sales - Sales Commissions



