Ibm Db2 vulnerabilities
353 known vulnerabilities affecting ibm/db2.
Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16
Vulnerabilities
Page 18 of 18
CVE-2010-3732P4LOWCVSS 3.5v9.52010-10-05
CVE-2010-3732 [LOW] CWE-20 CVE-2010-3732: The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to caus
The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.
nvd
CVE-2007-1228P4MEDIUMCVSS 4.4v8.2v9.02007-03-02
CVE-2007-1228 [MEDIUM] CWE-287 CVE-2007-1228: IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "f
IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.
nvd
CVE-2023-38719P4MEDIUMCVSS 4.4v11.5.82023-10-17
CVE-2023-38719 [MEDIUM] CWE-20 CVE-2023-38719: IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during da
IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation on DPF. IBM X-Force ID: 261607.
nvd
CVE-2017-1150P4LOWCVSS 3.1v10.1v10.5+1 more2017-03-08
CVE-2017-1150 [LOW] CWE-269 CVE-2017-1150: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow a
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.
nvd
CVE-2009-4150P4MEDIUMCVSS 4.6v9.1v9.5+1 more2009-12-02
CVE-2009-4150 [MEDIUM] CWE-264 CVE-2009-4150: dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits executi
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
nvd
CVE-2009-4334P4MEDIUMCVSS 4.6v9.1v9.5+1 more2009-12-16
CVE-2009-4334 [MEDIUM] CWE-264 CVE-2009-4334: The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 b
The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file.
nvd
CVE-2010-3196P4LOWCVSS 3.5v9.72010-08-31
CVE-2010-3196 [LOW] CWE-264 CVE-2010-3196: IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a d
IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.
nvd
CVE-2010-3737P4LOWCVSS 3.5v9.52010-10-05
CVE-2010-3737 [LOW] CWE-399 CVE-2010-3737: Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote a
Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while using a different code page than the database server.
nvd
CVE-2026-18096P4LOWCVSS 3.3v12.1.52026-08-12
CVE-2026-18096 [LOW] CWE-770 CVE-2026-18096: IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacke
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.
nvd
CVE-2010-3735P4LOWCVSS 2.1v9.52010-10-05
CVE-2010-3735 [LOW] CWE-399 CVE-2010-3735: The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote auth
The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.
nvd
CVE-2005-2073P4LOWCVSS 2.1v8.1.4v8.1.5+7 more2005-06-29
CVE-2005-2073 [LOW] CVE-2005-2073: Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with
Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.
nvd
CVE-2011-1373P4LOWCVSS 1.5≤ 9.7.0.4v9.7.0.1+2 more2011-11-09
CVE-2011-1373 [LOW] CVE-2011-1373: Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (ST
Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.
nvd
CVE-2014-4805P4LOWCVSS 2.1v10.5v10.5.0.1+2 more2014-09-04
CVE-2014-4805 [LOW] CWE-200 CVE-2014-4805: IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, w
IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.
nvd
← Previous18 / 18