cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 13 of 18
CVE-2008-0696P4HIGHCVSS 7.5v8.2_fixpack152008-02-12
CVE-2008-0696 [HIGH] CWE-264 CVE-2008-0696: IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.
nvd
CVE-2025-36428P4MEDIUMCVSS 5.3≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36428 [MEDIUM] CWE-1284 CVE-2025-36428: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.
nvd
CVE-2018-1452P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1452 [MEDIUM] CVE-2018-1452: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.
nvd
CVE-2018-1449P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1449 [MEDIUM] CVE-2018-1449: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.
nvd
CVE-2018-1450P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1450 [MEDIUM] CVE-2018-1450: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140045.
nvd
CVE-2018-1451P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-05-25
CVE-2018-1451 [MEDIUM] CVE-2018-1451: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140046.
nvd
CVE-2025-14688P4MEDIUMCVSS 5.3≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-04-30
CVE-2025-14688 [MEDIUM] CWE-1284 CVE-2025-14688: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
nvd
CVE-2007-1088P4HIGHCVSS 7.2v8.0v8.1+11 more2007-02-23
CVE-2007-1088 [HIGH] CWE-119 CVE-2007-1088: Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows loc Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.
nvd
CVE-2010-3733P4HIGHCVSS 7.2v9.52010-10-05
CVE-2010-3733 [HIGH] CWE-264 CVE-2010-3733: The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for th The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.
nvd
CVE-2017-1105P4HIGHCVSS 7.1v9.7v10.1+2 more2017-06-27
CVE-2017-1105 [HIGH] CWE-119 CVE-2017-1105: IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulne IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.
nvd
CVE-2010-3474P4MEDIUMCVSS 5.0v9.7v9.7.0.1+1 more2010-09-20
CVE-2010-3474 [MEDIUM] CVE-2010-3474: IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions u IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
nvd
CVE-2021-38926P4MEDIUMCVSS 5.5v9.7v10.1+3 more2021-12-09
CVE-2021-38926 [MEDIUM] CVE-2021-38926: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.
nvd
CVE-2026-18097P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.52026-08-12
CVE-2026-18097 [MEDIUM] CWE-532 CVE-2026-18097: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
nvd
CVE-2023-52296P4MEDIUMCVSS 5.3v11.52024-04-03
CVE-2023-52296 [MEDIUM] CWE-20 CVE-2023-52296: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of se IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently. IBM X-Force ID: 278547.
nvd
CVE-2025-13755P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-26
CVE-2025-13755 [MEDIUM] CWE-532 CVE-2025-13755: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
nvd
CVE-2024-41761P4MEDIUMCVSS 5.3v10.5v11.1+1 more2024-11-23
CVE-2024-41761 [MEDIUM] CWE-789 CVE-2024-41761: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2009-4331P4HIGHCVSS 7.2v9.5v9.72009-12-16
CVE-2009-4331 [HIGH] CWE-264 CVE-2009-4331: The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.
nvd
CVE-2012-1796P4HIGHCVSS 7.2v9.52012-03-20
CVE-2012-1796 [HIGH] CVE-2012-1796: Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 o Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
nvd
CVE-2008-0697P4HIGHCVSS 7.2v8.2_fixpack152008-02-12
CVE-2008-0697 [HIGH] CWE-264 CVE-2008-0697: Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain ro Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.
nvd
CVE-2010-3197P4MEDIUMCVSS 5.0v9.72010-08-31
CVE-2010-3197 [MEDIUM] CWE-264 CVE-2010-3197: IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative vi IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
Ibm Db2 vulnerabilities | cvebase