Ibm Db2 vulnerabilities
353 known vulnerabilities affecting ibm/db2.
Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16
Vulnerabilities
Page 14 of 18
CVE-2018-1799P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-11-09
CVE-2018-1799 [MEDIUM] CVE-2018-1799: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429.
nvd
CVE-2017-1571P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-03-22
CVE-2017-1571 [MEDIUM] CWE-327 CVE-2017-1571: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses wea
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
nvd
CVE-2024-40679P4MEDIUMCVSS 5.5v11.52025-01-08
CVE-2024-40679 [MEDIUM] CWE-532 CVE-2024-40679: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an informati
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
nvd
CVE-2025-1493P4MEDIUMCVSS 5.3≥ 12.1.0, ≤ 12.1.12025-05-05
CVE-2025-1493 [MEDIUM] CWE-362 CVE-2025-1493: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1
could allow an authenticated user to cause a denial of service due to concurrent execution of shared resources.
nvd
CVE-2014-8910P4MEDIUMCVSS 4.0v9.7v9.8+2 more2015-07-20
CVE-2014-8910 [MEDIUM] CWE-74 CVE-2014-8910: IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement.
nvd
CVE-2012-0710P4MEDIUMCVSS 5.0v9.1v9.5+2 more2012-03-20
CVE-2012-0710 [MEDIUM] CWE-20 CVE-2012-0710: IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers
IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.
nvd
CVE-2011-1847P4MEDIUMCVSS 4.9≤ 9.5v9.5+2 more2011-05-03
CVE-2011-1847 [MEDIUM] CWE-264 CVE-2011-1847: IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce priv
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information.
nvd
CVE-2018-1685P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-09-21
CVE-2018-1685 [MEDIUM] CWE-200 CVE-2018-1685: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
nvd
CVE-2025-36407P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36407 [MEDIUM] CWE-1284 CVE-2025-36407: IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE
IBM® Db2® is vulnerable to a denial of service with a specially crafted query that uses ALTER TABLE operations.
nvd
CVE-2018-1428P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-03-22
CVE-2018-1428 [MEDIUM] CWE-327 CVE-2018-1428: IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.
nvd
CVE-2024-25030P4MEDIUMCVSS 5.5v11.12024-04-03
CVE-2024-25030 [MEDIUM] CWE-532 CVE-2024-25030: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.
nvd
CVE-2013-4033P4MEDIUMCVSS 4.6v9.7v9.8+2 more2013-08-28
CVE-2013-4033 [MEDIUM] CWE-264 CVE-2013-4033: IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 all
IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.
nvd
CVE-2010-3475P4MEDIUMCVSS 4.0v9.7v9.7.0.1+1 more2010-09-20
CVE-2010-3475 [MEDIUM] CWE-264 CVE-2010-3475: IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in
IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.
nvd
CVE-2024-52894P4MEDIUMCVSS 4.9≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+2 more2025-07-29
CVE-2024-52894 [MEDIUM] CWE-121 CVE-2024-52894: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2008-3959P4MEDIUMCVSS 5.0≤ 8.1≤ 8.2+2 more2008-09-11
CVE-2008-3959 [MEDIUM] CVE-2008-3959: IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attack
IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.
nvd
CVE-2025-36423P4MEDIUMCVSS 5.5≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36423 [MEDIUM] CWE-1284 CVE-2025-36423: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a loca
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
nvd
CVE-2010-3734P4MEDIUMCVSS 5.0v9.52010-10-05
CVE-2010-3734 [MEDIUM] CWE-264 CVE-2010-3734: The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an uninten
The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.
nvd
CVE-2026-10695P4MEDIUMCVSS 5.5≥ 12.1.0, < 12.1.5≥ 12.1.0, ≤ 12.1.42026-07-30
CVE-2026-10695 [MEDIUM] CWE-400 CVE-2026-10695: IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
nvd
CVE-2026-6053P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-6053 [MEDIUM] CWE-770 CVE-2026-6053: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.
nvd
CVE-2010-3738P4MEDIUMCVSS 5.0v9.52010-10-05
CVE-2010-3738 [MEDIUM] CWE-264 CVE-2010-3738: The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUT
The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.
nvd