cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 11 of 17
CVE-2011-1846P4MEDIUMCVSS 6.5≤ 9.5v9.5+2 more2011-05-03
CVE-2011-1846 [MEDIUM] CVE-2011-1846: IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party informati
nvd
CVE-2020-4161P4MEDIUMCVSS 6.5v11.52020-02-19
CVE-2020-4161 [MEDIUM] CVE-2020-4161: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to incorrect handling of certain commands. IBM X-Force ID: 174341.
nvd
CVE-2023-30443P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-12-19
CVE-2023-30443 [MEDIUM] CWE-770 CVE-2023-30443: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.
nvd
CVE-2024-37071P4MEDIUMCVSS 6.5≥ 10.5.0, ≤ 10.5.11≥ 11.1.4, ≤ 11.1.4.7+1 more2024-12-07
CVE-2024-37071 [MEDIUM] CWE-789 CVE-2024-37071: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.
nvd
CVE-2025-36009P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36009 [MEDIUM] CWE-1284 CVE-2025-36009: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use of a global variable.
nvd
CVE-2025-0915P4MEDIUMCVSS 6.5≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.12025-05-05
CVE-2025-0915 [MEDIUM] CWE-770 CVE-2025-0915: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations could allow an authenticated user to cause a denial of service due to insufficient release of allocated memory resources.
nvd
CVE-2025-3050P4MEDIUMCVSS 6.5≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.12025-05-29
CVE-2025-3050 [MEDIUM] CWE-770 CVE-2025-3050: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service when using Q replication due to the improper allocation of CPU resources.
nvd
CVE-2019-4102P4MEDIUMCVSS 5.9v9.7.0.0v9.7.0.1+33 more2019-07-01
CVE-2019-4102 [MEDIUM] CWE-326 CVE-2019-4102: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses wea IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.
nvd
CVE-2007-5652P4HIGHCVSS 7.8≤ 9.1v9.12007-10-23
CVE-2007-5652 [HIGH] CWE-119 CVE-2007-5652: IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication information, which might allow attackers to cause a denial of service (instance crash) or trigger memory corruption. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
nvd
CVE-2012-2196P4MEDIUMCVSS 5.0v9.1v9.1.0.1+32 more2012-07-25
CVE-2012-2196 [MEDIUM] CWE-200 CVE-2012-2196: IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote a IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP_CFG_C2 stored procedure.
nvd
CVE-2008-3958P4HIGHCVSS 7.5≤ 8.0v8.02008-09-11
CVE-2008-3958 [HIGH] CVE-2008-3958: IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
nvd
CVE-2007-1087P4HIGHCVSS 7.2v8.0v8.1+11 more2007-02-23
CVE-2007-1087 [HIGH] CWE-119 CVE-2007-1087: IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
nvd
CVE-2009-3472P4MEDIUMCVSS 6.5v8.0v9.1+1 more2009-09-29
CVE-2009-3472 [MEDIUM] CWE-264 CVE-2009-3472: IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypas IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
nvd
CVE-2009-4438P4MEDIUMCVSS 6.5v9.1v9.5+1 more2009-12-28
CVE-2009-4438 [MEDIUM] CWE-264 CVE-2009-4438: The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.
nvd
CVE-2005-4869P4LOWCVSS 2.1PoCv8.12005-12-31
CVE-2005-4869 [LOW] CVE-2005-4869: The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of serv The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.
nvd
CVE-2025-1992P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9v12.1.0+1 more2025-05-05
CVE-2025-1992 [MEDIUM] CWE-401 CVE-2025-1992: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.
nvd
CVE-2020-4355P4MEDIUMCVSS 5.3v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4355 [MEDIUM] CVE-2020-4355: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service, caused by improper handling of Secure Sockets Layer (SSL) renegotiation requests. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to increase the resource usage on the system. IBM X-F
nvd
CVE-2014-0907P4HIGHCVSS 7.2v9.5v9.7+16 more2014-05-30
CVE-2014-0907 [HIGH] CVE-2014-0907: Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.
nvd
CVE-2009-4325P4MEDIUMCVSS 6.4v8.2v9.1+2 more2009-12-16
CVE-2009-4325 [MEDIUM] CWE-20 CVE-2009-4325: The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."
nvd
CVE-2016-0215P4MEDIUMCVSS 6.5v9.7v10.1+2 more2018-01-16
CVE-2016-0215 [MEDIUM] CWE-20 CVE-2016-0215: IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remot IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
nvd
Ibm Db2 vulnerabilities | cvebase