cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 12 of 18
CVE-2009-4438P4MEDIUMCVSS 6.5v9.1v9.5+1 more2009-12-28
CVE-2009-4438 [MEDIUM] CWE-264 CVE-2009-4438: The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.
nvd
CVE-2005-4869P4LOWCVSS 2.1PoCv8.12005-12-31
CVE-2005-4869 [LOW] CVE-2005-4869: The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of serv The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.
nvd
CVE-2025-1992P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9v12.1.0+1 more2025-05-05
CVE-2025-1992 [MEDIUM] CWE-401 CVE-2025-1992: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.
nvd
CVE-2020-4355P4MEDIUMCVSS 5.3v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4355 [MEDIUM] CVE-2020-4355: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service, caused by improper handling of Secure Sockets Layer (SSL) renegotiation requests. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to increase the resource usage on the system. IBM X-F
nvd
CVE-2008-3958P4HIGHCVSS 7.5≤ 8.0v8.02008-09-11
CVE-2008-3958 [HIGH] CVE-2008-3958: IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
nvd
CVE-2014-0907P4HIGHCVSS 7.2v9.5v9.7+16 more2014-05-30
CVE-2014-0907 [HIGH] CVE-2014-0907: Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.
nvd
CVE-2009-4325P4MEDIUMCVSS 6.4v8.2v9.1+2 more2009-12-16
CVE-2009-4325 [MEDIUM] CWE-20 CVE-2009-4325: The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."
nvd
CVE-2007-1087P4HIGHCVSS 7.2v8.0v8.1+11 more2007-02-23
CVE-2007-1087 [HIGH] CWE-119 CVE-2007-1087: IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.
nvd
CVE-2016-0215P4MEDIUMCVSS 6.5v9.7v10.1+2 more2018-01-16
CVE-2016-0215 [MEDIUM] CWE-20 CVE-2016-0215: IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remot IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
nvd
CVE-2020-4230P4MEDIUMCVSS 6.7v11.1v11.52020-02-19
CVE-2020-4230 [MEDIUM] CVE-2020-4230: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.
nvd
CVE-2026-86087P4MEDIUMCVSS 4.3≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.5+1 more2026-09-10
CVE-2026-86087 [MEDIUM] CWE-22 CVE-2026-86087: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
nvd
CVE-2012-2194P4MEDIUMCVSS 5.0v9.1v9.1.0.1+32 more2012-07-25
CVE-2012-2194 [MEDIUM] CWE-22 CVE-2012-2194: Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors.
nvd
CVE-2013-4032P4MEDIUMCVSS 5.0v10.1v10.52013-10-02
CVE-2013-4032 [MEDIUM] CWE-20 CVE-2013-4032: The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise S The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a multi-node configuration is used, allows remote attackers to cause a denial of service via vectors involving arbitrary data.
nvd
CVE-2015-0157P4MEDIUMCVSS 6.8v9.7v9.8+2 more2015-07-20
CVE-2015-0157 [MEDIUM] CWE-20 CVE-2015-0157: IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.
nvd
CVE-2005-4870P4MEDIUMCVSS 4.3v8.12005-12-31
CVE-2005-4870 [MEDIUM] CWE-119 CVE-2005-4870: Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarc Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument.
nvd
CVE-2017-1439P4MEDIUMCVSS 6.7v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1439 [MEDIUM] CVE-2017-1439: IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could al IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.
nvd
CVE-2017-1438P4MEDIUMCVSS 6.7v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1438 [MEDIUM] CVE-2017-1438: IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could al IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.
nvd
CVE-2017-1519P4MEDIUMCVSS 5.9v10.5v10.5.0.1+7 more2017-09-12
CVE-2017-1519 [MEDIUM] CWE-20 CVE-2017-1519: IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829.
nvd
CVE-2008-2154P4MEDIUMCVSS 6.0v8.0v9.1+1 more2009-06-03
CVE-2008-2154 [MEDIUM] CWE-16 CVE-2008-2154: IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_ IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.
nvd
CVE-2023-25930P4MEDIUMCVSS 5.9≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-28
CVE-2023-25930 [MEDIUM] CWE-20 CVE-2023-25930: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service. Under rare conditions, setting a special register may cause the Db2 server to terminate abnormally. IBM X-Force ID: 247862.
nvd
Ibm Db2 vulnerabilities | cvebase