Ibm Db2 vulnerabilities
340 known vulnerabilities affecting ibm/db2.
Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15
Vulnerabilities
Page 15 of 17
CVE-2015-1883P4MEDIUMCVSS 4.0v9.7v9.8+2 more2015-07-20
CVE-2015-1883 [MEDIUM] CWE-200 CVE-2015-1883: IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read certain administrative files via crafted use of an automated-maintenance policy stored procedure.
nvd
CVE-2023-23487P4MEDIUMCVSS 4.3v11.1v11.52023-07-10
CVE-2023-23487 [MEDIUM] CVE-2023-23487: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to ins
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918.
nvd
CVE-2010-0472P4MEDIUMCVSS 5.0v9.7.0.12010-02-02
CVE-2010-0472 [MEDIUM] CVE-2010-0472: kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attac
kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.
nvd
CVE-2009-2858P4MEDIUMCVSS 5.0≤ 8.1v8.12009-08-19
CVE-2009-2858 [MEDIUM] CWE-399 CVE-2009-2858: Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.
nvd
CVE-2012-2180P4MEDIUMCVSS 4.3v9.7v9.7.0.1+7 more2012-06-20
CVE-2012-2180 [MEDIUM] CVE-2012-2180: The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM
The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5 allows remote attackers to cause a denial of service (NULL pointer dereference, and resource consumption or daemon crash) via a crafted request.
nvd
CVE-2009-4326P4MEDIUMCVSS 4.3v9.5v9.72009-12-16
CVE-2009-4326 [MEDIUM] CWE-200 CVE-2009-4326: The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9
The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.
nvd
CVE-2013-6717P4MEDIUMCVSS 4.0v9.7v9.7.0.1+19 more2013-12-19
CVE-2013-6717 [MEDIUM] CVE-2013-6717: The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3,
The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP2, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service (database outage and deactivation) via unspecified vectors.
nvd
CVE-2020-4885P4MEDIUMCVSS 4.7v11.52021-06-24
CVE-2020-4885 [MEDIUM] CWE-59 CVE-2020-4885: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to a
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.
nvd
CVE-2011-4061P4MEDIUMCVSS 6.9v9.72011-10-18
CVE-2011-4061 [MEDIUM] CVE-2011-4061: Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Ed
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.
nvd
CVE-2012-0713P4LOWCVSS 3.5v9.7v9.7.0.1+4 more2012-08-24
CVE-2012-0713 [LOW] CVE-2012-0713: Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows a
Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vectors.
nvd
CVE-2009-4332P4MEDIUMCVSS 5.0v9.1v9.5+1 more2009-12-16
CVE-2009-4332 [MEDIUM] CVE-2009-4332: db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows att
db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer dereference and application termination) via unspecified vectors.
nvd
CVE-2018-1427P4MEDIUMCVSS 5.5v9.7v10.1+2 more2018-03-22
CVE-2018-1427 [MEDIUM] CWE-119 CVE-2018-1427: IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environme
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a local attacker could overflow and cause a denial of service. IBM X-Force ID: 139072.
nvd
CVE-2020-4642P4MEDIUMCVSS 5.5v9.7v10.1+3 more2020-12-23
CVE-2020-4642 [MEDIUM] CVE-2020-4642: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".
nvd
CVE-2008-4693P4MEDIUMCVSS 5.0≤ 9.1≤ 9.5+2 more2008-10-22
CVE-2008-4693 [MEDIUM] CWE-200 CVE-2008-4693: The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive infor
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."
nvd
CVE-2021-29763P4MEDIUMCVSS 5.1v11.1v11.52021-09-16
CVE-2021-29763 [MEDIUM] CWE-770 CVE-2021-29763: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.
nvd
CVE-2020-4386P4MEDIUMCVSS 4.7v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4386 [MEDIUM] CWE-362 CVE-2020-4386: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179268.
nvd
CVE-2020-4387P4MEDIUMCVSS 4.7v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4387 [MEDIUM] CWE-362 CVE-2020-4387: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179269.
nvd
CVE-2014-0919P4MEDIUMCVSS 4.0v9.5v9.7+3 more2015-05-08
CVE-2014-0919 [MEDIUM] CWE-200 CVE-2014-0919: IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certa
IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.
nvd
CVE-2020-4976P4MEDIUMCVSS 4.4≥ 11.1.0.0, < 11.1.4.6≥ 11.5, < 11.5.5.0+3 more2021-03-11
CVE-2020-4976 [MEDIUM] CWE-276 CVE-2020-4976: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.
nvd
CVE-2010-3195P4MEDIUMCVSS 5.0v9.1v9.5+1 more2010-08-31
CVE-2010-3195 [MEDIUM] CVE-2010-3195: Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows S
Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors involving "special group and user enumeration."
nvd