cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 12 of 17
CVE-2020-4230P4MEDIUMCVSS 6.7v11.1v11.52020-02-19
CVE-2020-4230 [MEDIUM] CVE-2020-4230: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.
nvd
CVE-2012-2194P4MEDIUMCVSS 5.0v9.1v9.1.0.1+32 more2012-07-25
CVE-2012-2194 [MEDIUM] CWE-22 CVE-2012-2194: Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to replace JAR files via unspecified vectors.
nvd
CVE-2013-4032P4MEDIUMCVSS 5.0v10.1v10.52013-10-02
CVE-2013-4032 [MEDIUM] CWE-20 CVE-2013-4032: The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise S The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a multi-node configuration is used, allows remote attackers to cause a denial of service via vectors involving arbitrary data.
nvd
CVE-2015-0157P4MEDIUMCVSS 6.8v9.7v9.8+2 more2015-07-20
CVE-2015-0157 [MEDIUM] CWE-20 CVE-2015-0157: IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.
nvd
CVE-2005-4870P4MEDIUMCVSS 4.3v8.12005-12-31
CVE-2005-4870 [MEDIUM] CWE-119 CVE-2005-4870: Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarc Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument.
nvd
CVE-2017-1439P4MEDIUMCVSS 6.7v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1439 [MEDIUM] CVE-2017-1439: IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could al IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.
nvd
CVE-2017-1438P4MEDIUMCVSS 6.7v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1438 [MEDIUM] CVE-2017-1438: IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could al IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.
nvd
CVE-2017-1519P4MEDIUMCVSS 5.9v10.5v10.5.0.1+7 more2017-09-12
CVE-2017-1519 [MEDIUM] CWE-20 CVE-2017-1519: IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829.
nvd
CVE-2008-2154P4MEDIUMCVSS 6.0v8.0v9.1+1 more2009-06-03
CVE-2008-2154 [MEDIUM] CWE-16 CVE-2008-2154: IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_ IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.
nvd
CVE-2023-25930P4MEDIUMCVSS 5.9≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-28
CVE-2023-25930 [MEDIUM] CWE-20 CVE-2023-25930: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service. Under rare conditions, setting a special register may cause the Db2 server to terminate abnormally. IBM X-Force ID: 247862.
nvd
CVE-2008-0696P4HIGHCVSS 7.5v8.2_fixpack152008-02-12
CVE-2008-0696 [HIGH] CWE-264 CVE-2008-0696: IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.
nvd
CVE-2025-36428P4MEDIUMCVSS 5.3≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36428 [MEDIUM] CWE-1284 CVE-2025-36428: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.
nvd
CVE-2018-1452P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1452 [MEDIUM] CVE-2018-1452: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.
nvd
CVE-2018-1449P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1449 [MEDIUM] CVE-2018-1449: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.
nvd
CVE-2018-1450P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1450 [MEDIUM] CVE-2018-1450: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140045.
nvd
CVE-2018-1451P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1451 [MEDIUM] CVE-2018-1451: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140046.
nvd
CVE-2025-14688P4MEDIUMCVSS 5.3≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-04-30
CVE-2025-14688 [MEDIUM] CWE-1284 CVE-2025-14688: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
nvd
CVE-2007-1088P4HIGHCVSS 7.2v8.0v8.1+11 more2007-02-23
CVE-2007-1088 [HIGH] CWE-119 CVE-2007-1088: Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows loc Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.
nvd
CVE-2010-3733P4HIGHCVSS 7.2v9.52010-10-05
CVE-2010-3733 [HIGH] CWE-264 CVE-2010-3733: The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for th The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.
nvd
CVE-2017-1105P4HIGHCVSS 7.1v9.7v10.1+2 more2017-06-27
CVE-2017-1105 [HIGH] CWE-119 CVE-2017-1105: IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulne IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.
nvd
Ibm Db2 vulnerabilities | cvebase