Multiple Buffer Overflow Vulnerabilities in IBM Database Software (DB2 and Informix)
During the last couple of weeks we have published security vulnerabilities in database tools related to DB2 and Informix databases.
We’re sure that you (as responsible database admin) usually don’t run arbitrary “attacker supplied” .SQL files on your database. But even more, after security audit results of Informix and DB2 database tools, we’re sure that you want to add extra care on that one, since we’ve discovered that poisonous .SQL files can overflow database tools memory buffers and execute arbitrary code on your system.
Links to our advisories are listed below:
Informix Security Advisory:
DB2 Security Advisory:
- DefenseCode ThunderScan SAST 2.1.0 added support for Go and ABAP languages
- ThunderScan Enterprise SAST Now Supports Linux
- DefenseCode ThunderScan Added Support for COBOL
- DefenseCode ThunderScan SAST Added Support for Groovy, TypeScript and ColdFusion
- DefenseCode Appoints Harry Dehaly as Global Director of Sales