cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 14 of 17
CVE-2024-25030P4MEDIUMCVSS 5.5v11.12024-04-03
CVE-2024-25030 [MEDIUM] CWE-532 CVE-2024-25030: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.
nvd
CVE-2010-3475P4MEDIUMCVSS 4.0v9.7v9.7.0.1+1 more2010-09-20
CVE-2010-3475 [MEDIUM] CWE-264 CVE-2010-3475: IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.
nvd
CVE-2024-52894P4MEDIUMCVSS 4.9≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+2 more2025-07-29
CVE-2024-52894 [MEDIUM] CWE-121 CVE-2024-52894: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2008-3959P4MEDIUMCVSS 5.0≤ 8.1≤ 8.2+2 more2008-09-11
CVE-2008-3959 [MEDIUM] CVE-2008-3959: IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attack IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request.
nvd
CVE-2025-36423P4MEDIUMCVSS 5.5≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36423 [MEDIUM] CWE-1284 CVE-2025-36423: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a loca IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
nvd
CVE-2010-3734P4MEDIUMCVSS 5.0v9.52010-10-05
CVE-2010-3734 [MEDIUM] CWE-264 CVE-2010-3734: The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an uninten The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.
nvd
CVE-2026-7771P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, < 12.1.5+1 more2026-07-17
CVE-2026-7771 [MEDIUM] CWE-835 CVE-2026-7771: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a sp IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial of service.
nvd
CVE-2026-6053P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-6053 [MEDIUM] CWE-770 CVE-2026-6053: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.
nvd
CVE-2010-3738P4MEDIUMCVSS 5.0v9.52010-10-05
CVE-2010-3738 [MEDIUM] CWE-264 CVE-2010-3738: The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUT The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.
nvd
CVE-2012-0709P4MEDIUMCVSS 4.0v9.5v9.7+1 more2012-03-20
CVE-2012-0709 [MEDIUM] CWE-20 CVE-2012-0709: IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, whic IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.
nvd
CVE-2025-36131P4MEDIUMCVSS 4.6≥ 11.1.0, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.9+1 more2025-11-07
CVE-2025-36131 [MEDIUM] CWE-359 CVE-2025-36131: IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX an IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party with physical access to the system.
nvd
CVE-2009-4327P4MEDIUMCVSS 5.0v9.5v9.72009-12-16
CVE-2009-4327 [MEDIUM] CWE-20 CVE-2009-4327: The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not prope The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvd
CVE-2009-1905P4LOWCVSS 2.6≤ 8.0≤ 9.1+3 more2009-06-03
CVE-2009-1905 [LOW] CWE-287 CVE-2009-1905: The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.
nvd
CVE-2019-4101P4MEDIUMCVSS 5.5v9.7.0.0v9.7.0.1+33 more2019-07-01
CVE-2019-4101 [MEDIUM] CVE-2019-4101: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of service. Users that have both EXECUTE on PD_GET_DIAG_HIST and access to the diagnostic directory on the DB2 server can cause the instance to crash. IBM X-Force ID: 158091.
nvd
CVE-2025-36353P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36353 [MEDIUM] CWE-943 CVE-2025-36353: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
nvd
CVE-2025-36123P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36123 [MEDIUM] CWE-770 CVE-2025-36123: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service when copying large table containing XML data due to improper allocation of system resources.
nvd
CVE-2025-36185P4MEDIUMCVSS 5.5≥ 12.1.0, ≤ 12.1.22025-11-07
CVE-2025-36185 [MEDIUM] CWE-943 CVE-2025-36185: IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.
nvd
CVE-2025-36136P4MEDIUMCVSS 5.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32025-11-07
CVE-2025-36136 [MEDIUM] CWE-770 CVE-2025-36136: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause a denial of service due to the database monitor script incorrectly detecting that the instance is still starting under specific conditions.
nvd
CVE-2009-4330P4HIGHCVSS 7.2v9.52009-12-16
CVE-2009-4330 [HIGH] CVE-2009-4330: Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.
nvd
CVE-2021-29752P4MEDIUMCVSS 4.4v11.2v11.52021-09-16
CVE-2021-29752 [MEDIUM] CVE-2021-29752: IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage cred IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.
nvd
Ibm Db2 vulnerabilities | cvebase