cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 13 of 17
CVE-2010-3474P4MEDIUMCVSS 5.0v9.7v9.7.0.1+1 more2010-09-20
CVE-2010-3474 [MEDIUM] CVE-2010-3474: IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions u IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
nvd
CVE-2021-38926P4MEDIUMCVSS 5.5v9.7v10.1+3 more2021-12-09
CVE-2021-38926 [MEDIUM] CVE-2021-38926: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.
nvd
CVE-2023-52296P4MEDIUMCVSS 5.3v11.52024-04-03
CVE-2023-52296 [MEDIUM] CWE-20 CVE-2023-52296: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of se IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently. IBM X-Force ID: 278547.
nvd
CVE-2025-13755P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-26
CVE-2025-13755 [MEDIUM] CWE-532 CVE-2025-13755: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
nvd
CVE-2024-41761P4MEDIUMCVSS 5.3v10.5v11.1+1 more2024-11-23
CVE-2024-41761 [MEDIUM] CWE-789 CVE-2024-41761: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2009-4331P4HIGHCVSS 7.2v9.5v9.72009-12-16
CVE-2009-4331 [HIGH] CWE-264 CVE-2009-4331: The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.
nvd
CVE-2012-1796P4HIGHCVSS 7.2v9.52012-03-20
CVE-2012-1796 [HIGH] CVE-2012-1796: Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 o Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
nvd
CVE-2008-0697P4HIGHCVSS 7.2v8.2_fixpack152008-02-12
CVE-2008-0697 [HIGH] CWE-264 CVE-2008-0697: Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain ro Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.
nvd
CVE-2010-3197P4MEDIUMCVSS 5.0v9.72010-08-31
CVE-2010-3197 [MEDIUM] CWE-264 CVE-2010-3197: IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative vi IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2018-1799P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-11-09
CVE-2018-1799 [MEDIUM] CVE-2018-1799: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429.
nvd
CVE-2017-1571P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-03-22
CVE-2017-1571 [MEDIUM] CWE-327 CVE-2017-1571: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses wea IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
nvd
CVE-2024-40679P4MEDIUMCVSS 5.5v11.52025-01-08
CVE-2024-40679 [MEDIUM] CWE-532 CVE-2024-40679: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an informati IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
nvd
CVE-2025-1493P4MEDIUMCVSS 5.3≥ 12.1.0, ≤ 12.1.12025-05-05
CVE-2025-1493 [MEDIUM] CWE-362 CVE-2025-1493: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service due to concurrent execution of shared resources.
nvd
CVE-2013-4033P4MEDIUMCVSS 4.6v9.7v9.8+2 more2013-08-28
CVE-2013-4033 [MEDIUM] CWE-264 CVE-2013-4033: IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 all IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.
nvd
CVE-2014-8910P4MEDIUMCVSS 4.0v9.7v9.8+2 more2015-07-20
CVE-2014-8910 [MEDIUM] CWE-74 CVE-2014-8910: IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement.
nvd
CVE-2012-0710P4MEDIUMCVSS 5.0v9.1v9.5+2 more2012-03-20
CVE-2012-0710 [MEDIUM] CWE-20 CVE-2012-0710: IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.
nvd
CVE-2011-1847P4MEDIUMCVSS 4.9≤ 9.5v9.5+2 more2011-05-03
CVE-2011-1847 [MEDIUM] CWE-264 CVE-2011-1847: IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce priv IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information.
nvd
CVE-2018-1685P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-09-21
CVE-2018-1685 [MEDIUM] CWE-200 CVE-2018-1685: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
nvd
CVE-2018-1428P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-03-22
CVE-2018-1428 [MEDIUM] CWE-327 CVE-2018-1428: IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.
nvd
CVE-2025-36407P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36407 [MEDIUM] CWE-1284 CVE-2025-36407: IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
nvd
Ibm Db2 vulnerabilities | cvebase