Security readout for executives and security teams
CVE-2012-0710 is a denial-of-service flaw in older IBM DB2 releases. A remote attacker could send a crafted DRDA request that crashes a DB2 daemon, potentially interrupting applications that depend on the database. The sources do not indicate data theft or code execution. Exposure is most likely where legacy DB2 9.x systems remain deployed and accept remote DRDA connections. Internet-facing or broadly reachable database listeners raise business risk. Systems already at the listed fix-pack levels or later are not indicated as affected by the bundle. Treat this as a legacy database availability issue. Prioritize externally reachable or business-critical DB2 systems first. The urgency is lower than a confirmed exploited code-execution bug, but unpatched production databases can still create outage risk. Mitigation focus: Upgrade DB2 9.1 to FP11 or later if still in use.; Upgrade DB2 9.5 to FP9 or later if still in use.; Upgrade DB2 9.7 to FP5 or later if still in use..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Database behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2012-0710 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- db2-drda-dos(73494)CVE reference · vdb-entry, x_refsource_XF
- oval:org.mitre.oval:def:15078CVE reference · vdb-entry, signature
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
