cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 10 of 17
CVE-2024-41762P4MEDIUMCVSS 6.5≥ 10.5.0, ≤ 10.5.11≥ 11.1.4, ≤ 11.1.4.7+1 more2024-12-07
CVE-2024-41762 [MEDIUM] CWE-789 CVE-2024-41762: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-2668P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.92026-01-30
CVE-2025-2668 [MEDIUM] CWE-789 CVE-2025-2668: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when an authenticated user creates a specially crafted query.
nvd
CVE-2025-1000P4MEDIUMCVSS 6.5≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.12025-05-05
CVE-2025-1000 [MEDIUM] CWE-770 CVE-2025-1000: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service when connecting to a z/OS database due to improper handling of automatic client rerouting.
nvd
CVE-2025-36427P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36427 [MEDIUM] CWE-1284 CVE-2025-36427: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a deni IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.
nvd
CVE-2025-14689P4MEDIUMCVSS 6.5≥ 12.1.0, ≤ 12.1.32026-02-17
CVE-2025-14689 [MEDIUM] CWE-1284 CVE-2025-14689: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic with federated objects.
nvd
CVE-2025-13867P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-02-17
CVE-2025-13867 [MEDIUM] CWE-1284 CVE-2025-13867: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic
nvd
CVE-2023-33854P4MEDIUMCVSS 5.3≥ 4.8, < 5.42026-06-22
CVE-2023-33854 [MEDIUM] CWE-294 CVE-2023-33854: IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, a IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.
nvd
CVE-2011-0757P4MEDIUMCVSS 6.5≤ 9.1v9.1+4 more2011-02-02
CVE-2011-0757 [MEDIUM] CWE-264 CVE-2011-0757: IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not pr IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.
nvd
CVE-2013-3475P4HIGHCVSS 7.2v9.1v9.5+3 more2013-06-05
CVE-2013-3475 [HIGH] CWE-119 CVE-2013-3475: Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7 Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.
nvd
CVE-2018-1448P4HIGHCVSS 7.1v9.7v10.1+2 more2018-03-22
CVE-2018-1448 [HIGH] CVE-2018-1448: IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140043.
nvd
CVE-2018-1515P4HIGHCVSS 7.0v10.5v11.12018-05-25
CVE-2018-1515 [HIGH] CWE-119 CVE-2018-1515: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or u IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 141624.
nvd
CVE-2023-50308P4MEDIUMCVSS 6.5fixed in 11.5.92024-01-22
CVE-2023-50308 [MEDIUM] CWE-20 CVE-2023-50308: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances c IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database to cause a denial of service when a statement is run on columnar tables. IBM X-Force ID: 273393.
nvd
CVE-2024-35152P4MEDIUMCVSS 6.5v11.5.8v11.5.92024-08-14
CVE-2024-35152 [MEDIUM] CWE-789 CVE-2024-35152: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 292639.
nvd
CVE-2024-37529P4MEDIUMCVSS 6.5≥ 11.1.4, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.92024-08-14
CVE-2024-37529 [MEDIUM] CWE-789 CVE-2024-37529: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authe IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID: 294295.
nvd
CVE-2025-36366P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36366 [MEDIUM] CWE-943 CVE-2025-36366: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a deni IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that invokes the JSON_Object scalar function, which may trigger an unhandled exception leading to abnormal server termination.
nvd
CVE-2025-36098P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36098 [MEDIUM] CWE-770 CVE-2025-36098: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.
nvd
CVE-2025-36387P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.92026-01-30
CVE-2025-36387 [MEDIUM] CWE-770 CVE-2025-36387: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an aut IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query.
nvd
CVE-2025-36008P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32025-11-07
CVE-2025-36008 [MEDIUM] CWE-770 CVE-2025-36008: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper allocation of resources.
nvd
CVE-2008-0698P4HIGHCVSS 7.8v8.2_fixpack152008-02-12
CVE-2008-0698 [HIGH] CWE-119 CVE-2008-0698: Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, an Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."
nvd
CVE-2012-1797P4CRITICALCVSS 10.0v9.52012-03-20
CVE-2012-1797 [CRITICAL] CWE-264 CVE-2012-1797: IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack v IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.
nvd
Ibm Db2 vulnerabilities | cvebase