cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 1 of 17
CVE-2026-10109P2CRITICALCVSS 9.8≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-06-30
CVE-2026-10109 [CRITICAL] CWE-94 CVE-2026-10109: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.
nvd
CVE-2017-1297P3HIGHCVSS 7.3PoCv9.7v10.1+2 more2017-06-27
CVE-2017-1297 [HIGH] CWE-119 CVE-2017-1297: IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulne IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
nvd
CVE-2010-0462P3MEDIUMCVSS 6.5PoCv9.1v9.5+1 more2010-01-28
CVE-2010-0462 [MEDIUM] CWE-119 CVE-2010-0462: Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remo Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.
nvd
CVE-2007-2582P3CRITICALCVSS 10.0≤ 9.02007-05-10
CVE-2007-2582 [CRITICAL] CWE-119 CVE-2007-2582: Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow."
nvd
CVE-2023-27867P3HIGHCVSS 8.8v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-27867 [HIGH] CWE-94 CVE-2023-27867: IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote au IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Forc
nvd
CVE-2023-27868P3HIGHCVSS 8.8v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-27868 [HIGH] CWE-94 CVE-2023-27868: IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote au IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerabi
nvd
CVE-2023-27869P3HIGHCVSS 8.8v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-27869 [HIGH] CWE-94 CVE-2023-27869: IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote au IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on th
nvd
CVE-2010-3731P3CRITICALCVSS 10.0v9.52010-10-05
CVE-2010-3731 [CRITICAL] CWE-119 CVE-2010-3731: Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.
nvd
CVE-2025-33012P3HIGHCVSS 8.8≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+3 more2025-11-07
CVE-2025-33012 [HIGH] CWE-324 CVE-2025-33012: IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 1 IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.
nvd
CVE-2025-36365P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36365 [HIGH] CWE-639 CVE-2025-36365: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remote storage aliases could allow an authenticated user to execute unauthorized commands due to an authorization bypass vulnerability using a user-controlled key.
nvd
CVE-2025-36247P3HIGHCVSS 8.2≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-02-17
CVE-2025-36247 [HIGH] CWE-611 CVE-2025-36247: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2014-3094P3HIGHCVSS 8.5v9.7v9.7.0.1+21 more2014-09-04
CVE-2014-3094 [HIGH] CWE-119 CVE-2014-3094: Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.
nvd
CVE-2003-1051P4HIGHCVSS 7.2PoCv9.02004-09-28
CVE-2003-1051 [HIGH] CVE-2003-1051: Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to ex Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.
nvd
CVE-2012-4826P3HIGHCVSS 8.5v9.1v9.5+9 more2012-10-20
CVE-2012-4826 [HIGH] CWE-119 CVE-2012-4826: Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.
nvd
CVE-2003-1052P4HIGHCVSS 7.2PoCv9.02004-09-28
CVE-2003-1052 [HIGH] CVE-2003-1052: IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries tha IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
nvd
CVE-2023-42005P3HIGHCVSS 8.8v3.5v4.0+4 more2024-05-29
CVE-2023-42005 [HIGH] CWE-264 CVE-2023-42005: IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4 IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.
nvd
CVE-2026-9762P3HIGHCVSS 7.8≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, < 12.1.5+1 more2026-07-17
CVE-2026-9762 [HIGH] CWE-94 CVE-2026-9762: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
nvd
CVE-2025-36184P3HIGHCVSS 7.2≥ 11.5.0, ≤ 11.5.92026-01-30
CVE-2025-36184 [HIGH] CWE-250 CVE-2025-36184: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an ins IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
nvd
CVE-2012-0711P3HIGHCVSS 7.5v9.1v9.5+1 more2012-03-20
CVE-2012-0711 [HIGH] CWE-189 CVE-2012-0711: Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.
nvd
CVE-2008-0699P3CRITICALCVSS 9.0v8.2v9.1+1 more2008-02-12
CVE-2008-0699 [CRITICAL] CVE-2008-0699: Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.
nvd
1 / 17Next →
Ibm Db2 vulnerabilities | cvebase