Ibm Db2 vulnerabilities
340 known vulnerabilities affecting ibm/db2.
Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15
Vulnerabilities
Page 16 of 17
CVE-2009-2860P4MEDIUMCVSS 5.0≤ 8.1v8.12009-08-19
CVE-2009-2860 [MEDIUM] CVE-2009-2860: Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a de
Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
nvd
CVE-2008-4691P4MEDIUMCVSS 5.0≤ 9.1v9.12008-10-22
CVE-2008-4691 [MEDIUM] CVE-2008-4691: Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst
Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors.
nvd
CVE-2009-1239P4MEDIUMCVSS 5.0≤ 9.1v9.12009-04-03
CVE-2009-1239 [MEDIUM] CWE-200 CVE-2009-1239: IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of
IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.
nvd
CVE-2016-0211P4MEDIUMCVSS 4.3v9.8v9.8.0.1+30 more2016-04-28
CVE-2016-0211 [MEDIUM] CWE-20 CVE-2016-0211: IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows al
IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.
nvd
CVE-2014-8901P4MEDIUMCVSS 4.0v9.5v9.7+3 more2014-12-18
CVE-2014-8901 [MEDIUM] CWE-399 CVE-2014-8901: IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 a
IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted XML query.
nvd
CVE-2015-1922P4LOWCVSS 3.5v9.7v9.8+2 more2015-07-20
CVE-2015-1922 [LOW] CWE-284 CVE-2015-1922: The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and
The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors.
nvd
CVE-2014-6210P4MEDIUMCVSS 4.0v9.7v9.82014-12-12
CVE-2014-6210 [MEDIUM] CWE-20 CVE-2014-6210: IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying the same column within multiple ALTER TABLE statements.
nvd
CVE-2014-6209P4MEDIUMCVSS 4.0v9.5v9.7+2 more2014-12-12
CVE-2014-6209 [MEDIUM] CWE-20 CVE-2014-6209: IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 o
IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying an identity column within a crafted ALTER TABLE statement.
nvd
CVE-2013-5466P4MEDIUMCVSS 4.0v9.5v9.7+3 more2013-12-18
CVE-2013-5466 [MEDIUM] CVE-2013-5466: The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for
The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors.
nvd
CVE-2017-1434P4MEDIUMCVSS 4.7v11.1.0.02017-09-12
CVE-2017-1434 [MEDIUM] CWE-200 CVE-2017-1434: IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances,
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.
nvd
CVE-2009-4329P4MEDIUMCVSS 4.0v9.52009-12-16
CVE-2009-4329 [MEDIUM] CVE-2009-4329: Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote
Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (segmentation fault) by modifying the db2ra data stream sent in a request from the Load Utility.
nvd
CVE-2009-4328P4MEDIUMCVSS 4.0v9.52009-12-16
CVE-2009-4328 [MEDIUM] CVE-2009-4328: Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote aut
Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances.
nvd
CVE-2014-6097P4MEDIUMCVSS 4.0v9.7v9.82014-11-08
CVE-2014-6097 [MEDIUM] CWE-20 CVE-2014-6097: IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated
IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement.
nvd
CVE-2005-4871P4MEDIUMCVSS 4.3v8.12005-12-31
CVE-2005-4871 [MEDIUM] CWE-264 CVE-2005-4871: Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, w
Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile.
nvd
CVE-2020-4414P4MEDIUMCVSS 4.4v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4414 [MEDIUM] CVE-2020-4414: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of servic
nvd
CVE-2017-1520P4LOWCVSS 3.7v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1520 [LOW] CWE-287 CVE-2017-1520: IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.
nvd
CVE-2009-1906P4MEDIUMCVSS 4.3v9.1v9.52009-06-03
CVE-2009-1906 [MEDIUM] CVE-2009-1906: The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to
The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.
nvd
CVE-2008-1966P4MEDIUMCVSS 4.0v8.0v9.5+1 more2008-04-27
CVE-2008-1966 [MEDIUM] CWE-119 CVE-2008-1966: Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IB
Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_ja
nvd
CVE-2009-4439P4MEDIUMCVSS 4.0v9.52009-12-28
CVE-2009-4439 [MEDIUM] CVE-2009-4439: Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 bef
Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compiling a SQL query.
nvd
CVE-2009-2859P4MEDIUMCVSS 4.6≤ 8.1v8.12009-08-19
CVE-2009-2859 [MEDIUM] CWE-264 CVE-2009-2859: IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.
nvd