The host is installed with IBM DB2 9.1 before FP12 or 9.5 through FP9 or 9.7 through FP6 or 9.8 through FP5 or 10.1 and is prone to security bypass vulnerability. A flaw is present in the application, which fails to handle the GET_WRAP_CFG_C or GET_WRAP_CFG_C2 stored procedure. Successful exploitation allows attackers to read arbitrary XML files.