Ibm Db2 vulnerabilities
332 known vulnerabilities affecting ibm/db2.
Total CVEs
332
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH142MEDIUM162LOW15
Vulnerabilities
Page 14 of 17
CVE-2011-0731HIGHCVSS 7.5≤ 9.1v9.1+4 more2011-02-01
CVE-2011-0731 [HIGH] CWE-119 CVE-2011-0731: Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 bef
Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2010-3731CRITICALCVSS 10.0v9.52010-10-05
CVE-2010-3731 [CRITICAL] CWE-119 CVE-2010-3731: Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd
Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.
nvd
CVE-2010-3733HIGHCVSS 7.2v9.52010-10-05
CVE-2010-3733 [HIGH] CWE-264 CVE-2010-3733: The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for th
The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.
nvd
CVE-2010-3738MEDIUMCVSS 5.0v9.52010-10-05
CVE-2010-3738 [MEDIUM] CWE-264 CVE-2010-3738: The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUT
The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.
nvd
CVE-2010-3740MEDIUMCVSS 4.0v9.52010-10-05
CVE-2010-3740 [MEDIUM] CWE-399 CVE-2010-3740: The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before
The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and system hang) via the db2ext.textSearch function.
nvd
CVE-2010-3734MEDIUMCVSS 5.0v9.52010-10-05
CVE-2010-3734 [MEDIUM] CWE-264 CVE-2010-3734: The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an uninten
The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.
nvd
CVE-2010-3736MEDIUMCVSS 4.0v9.52010-10-05
CVE-2010-3736 [MEDIUM] CWE-399 CVE-2010-3736: Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the conne
Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the connection concentrator is enabled, allows remote authenticated users to cause a denial of service (heap memory consumption) by using a different code page than the database server.
nvd
CVE-2010-3737LOWCVSS 3.5v9.52010-10-05
CVE-2010-3737 [LOW] CWE-399 CVE-2010-3737: Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote a
Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while using a different code page than the database server.
nvd
CVE-2010-3735LOWCVSS 2.1v9.52010-10-05
CVE-2010-3735 [LOW] CWE-399 CVE-2010-3735: The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote auth
The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.
nvd
CVE-2010-3732LOWCVSS 3.5v9.52010-10-05
CVE-2010-3732 [LOW] CWE-20 CVE-2010-3732: The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to caus
The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.
nvd
CVE-2010-3474MEDIUMCVSS 5.0v9.7v9.7.0.1+1 more2010-09-20
CVE-2010-3474 [MEDIUM] CVE-2010-3474: IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions u
IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypass intended access restrictions via calls to these functions, a different vulnerability than CVE-2009-3471.
nvd
CVE-2010-3475MEDIUMCVSS 4.0v9.7v9.7.0.1+1 more2010-09-20
CVE-2010-3475 [MEDIUM] CWE-264 CVE-2010-3475: IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in
IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.
nvd
CVE-2010-3193CRITICALCVSS 10.0v9.1v9.5+1 more2010-08-31
CVE-2010-3193 [CRITICAL] CVE-2010-3193: Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7
Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.
nvd
CVE-2010-3194HIGHCVSS 7.5v9.1v9.5+1 more2010-08-31
CVE-2010-3194 [HIGH] CWE-264 CVE-2010-3194: The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers t
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
nvd
CVE-2010-3195MEDIUMCVSS 5.0v9.1v9.5+1 more2010-08-31
CVE-2010-3195 [MEDIUM] CVE-2010-3195: Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows S
Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors involving "special group and user enumeration."
nvd
CVE-2010-3197MEDIUMCVSS 5.0v9.72010-08-31
CVE-2010-3197 [MEDIUM] CWE-264 CVE-2010-3197: IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative vi
IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2010-3196LOWCVSS 3.5v9.72010-08-31
CVE-2010-3196 [LOW] CWE-264 CVE-2010-3196: IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a d
IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.
nvd
CVE-2010-1560MEDIUMCVSS 4.0≤ 9.1v9.12010-04-27
CVE-2010-1560 [MEDIUM] CVE-2010-1560: Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users t
Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.
nvd
CVE-2010-0472MEDIUMCVSS 5.0v9.7.0.12010-02-02
CVE-2010-0472 [MEDIUM] CVE-2010-0472: kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attac
kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.
nvd
CVE-2010-0462MEDIUMCVSS 6.5PoCv9.1v9.5+1 more2010-01-28
CVE-2010-0462 [MEDIUM] CWE-119 CVE-2010-0462: Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remo
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.
nvd