cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 11 of 18
CVE-2025-36366P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36366 [MEDIUM] CWE-943 CVE-2025-36366: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a deni IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that invokes the JSON_Object scalar function, which may trigger an unhandled exception leading to abnormal server termination.
nvd
CVE-2025-36098P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36098 [MEDIUM] CWE-770 CVE-2025-36098: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.
nvd
CVE-2025-36427P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36427 [MEDIUM] CWE-1284 CVE-2025-36427: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a deni IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.
nvd
CVE-2025-36387P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.92026-01-30
CVE-2025-36387 [MEDIUM] CWE-770 CVE-2025-36387: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an aut IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query.
nvd
CVE-2026-16702P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.52026-09-14
CVE-2026-16702 [MEDIUM] CWE-476 CVE-2026-16702: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.
nvd
CVE-2008-0698P4HIGHCVSS 7.8v8.2_fixpack152008-02-12
CVE-2008-0698 [HIGH] CWE-119 CVE-2008-0698: Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, an Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."
nvd
CVE-2012-1797P4CRITICALCVSS 10.0v9.52012-03-20
CVE-2012-1797 [CRITICAL] CWE-264 CVE-2012-1797: IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack v IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.
nvd
CVE-2023-33854P4MEDIUMCVSS 5.3≥ 4.8, < 5.42026-06-22
CVE-2023-33854 [MEDIUM] CWE-294 CVE-2023-33854: IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, a IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.
nvd
CVE-2011-1846P4MEDIUMCVSS 6.5≤ 9.5v9.5+2 more2011-05-03
CVE-2011-1846 [MEDIUM] CVE-2011-1846: IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party informati
nvd
CVE-2020-4161P4MEDIUMCVSS 6.5v11.52020-02-19
CVE-2020-4161 [MEDIUM] CVE-2020-4161: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to incorrect handling of certain commands. IBM X-Force ID: 174341.
nvd
CVE-2023-30443P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-12-19
CVE-2023-30443 [MEDIUM] CWE-770 CVE-2023-30443: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.
nvd
CVE-2025-0915P4MEDIUMCVSS 6.5≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.12025-05-05
CVE-2025-0915 [MEDIUM] CWE-770 CVE-2025-0915: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations could allow an authenticated user to cause a denial of service due to insufficient release of allocated memory resources.
nvd
CVE-2025-36009P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36009 [MEDIUM] CWE-1284 CVE-2025-36009: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use of a global variable.
nvd
CVE-2025-3050P4MEDIUMCVSS 6.5≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.12025-05-29
CVE-2025-3050 [MEDIUM] CWE-770 CVE-2025-3050: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service when using Q replication due to the improper allocation of CPU resources.
nvd
CVE-2024-37071P4MEDIUMCVSS 6.5≥ 10.5.0, ≤ 10.5.11≥ 11.1.4, ≤ 11.1.4.7+1 more2024-12-07
CVE-2024-37071 [MEDIUM] CWE-789 CVE-2024-37071: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.
nvd
CVE-2025-36008P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32025-11-07
CVE-2025-36008 [MEDIUM] CWE-770 CVE-2025-36008: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper allocation of resources.
nvd
CVE-2019-4102P4MEDIUMCVSS 5.9v9.7.0.0v9.7.0.1+33 more2019-07-01
CVE-2019-4102 [MEDIUM] CWE-326 CVE-2019-4102: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses wea IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.
nvd
CVE-2007-5652P4HIGHCVSS 7.8≤ 9.1v9.12007-10-23
CVE-2007-5652 [HIGH] CWE-119 CVE-2007-5652: IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication information, which might allow attackers to cause a denial of service (instance crash) or trigger memory corruption. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
nvd
CVE-2012-2196P4MEDIUMCVSS 5.0v9.1v9.1.0.1+32 more2012-07-25
CVE-2012-2196 [MEDIUM] CWE-200 CVE-2012-2196: IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote a IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP_CFG_C2 stored procedure.
nvd
CVE-2009-3472P4MEDIUMCVSS 6.5v8.0v9.1+1 more2009-09-29
CVE-2009-3472 [MEDIUM] CWE-264 CVE-2009-3472: IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypas IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
nvd
Ibm Db2 vulnerabilities | cvebase