Ibm Db2 vulnerabilities
353 known vulnerabilities affecting ibm/db2.
Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16
Vulnerabilities
Page 2 of 18
CVE-2026-9762P3HIGHCVSS 7.8≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, < 12.1.5+1 more2026-07-17
CVE-2026-9762 [HIGH] CWE-94 CVE-2026-9762: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
nvd
CVE-2025-36184P3HIGHCVSS 7.2≥ 11.5.0, ≤ 11.5.92026-01-30
CVE-2025-36184 [HIGH] CWE-250 CVE-2025-36184: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an ins
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
nvd
CVE-2026-87958P3HIGHCVSS 8.1≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.5+1 more2026-09-10
CVE-2026-87958 [HIGH] CWE-269 CVE-2026-87958: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
nvd
CVE-2012-0711P3HIGHCVSS 7.5v9.1v9.5+1 more2012-03-20
CVE-2012-0711 [HIGH] CWE-189 CVE-2012-0711: Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2
Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.
nvd
CVE-2023-29257P3HIGHCVSS 7.2≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-26
CVE-2023-29257 [HIGH] CVE-2023-29257: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance. IBM X-Force ID: 252011.
nvd
CVE-2018-1426P3CRITICALCVSS 9.1v9.7v10.1+2 more2018-03-22
CVE-2018-1426 [CRITICAL] CWE-335 CVE-2018-1426: IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.
nvd
CVE-2026-6938P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-6938 [HIGH] CWE-285 CVE-2026-6938: IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote objec
IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.
nvd
CVE-2008-0699P3CRITICALCVSS 9.0v8.2v9.1+1 more2008-02-12
CVE-2008-0699 [CRITICAL] CVE-2008-0699: Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2
Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.
nvd
CVE-2026-10535P3HIGHCVSS 7.8≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, < 12.1.5+1 more2026-07-30
CVE-2026-10535 [HIGH] CWE-121 CVE-2026-10535: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
nvd
CVE-2026-16480P3HIGHCVSS 7.1≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.5+1 more2026-08-12
CVE-2026-16480 [HIGH] CWE-602 CVE-2026-16480: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vu
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
nvd
CVE-2011-0731P3HIGHCVSS 7.5≤ 9.1v9.1+4 more2011-02-01
CVE-2011-0731 [HIGH] CWE-119 CVE-2011-0731: Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 bef
Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2025-33092P3HIGHCVSS 7.8v12.1.0v12.1.1+3 more2025-07-29
CVE-2025-33092 [HIGH] CWE-121 CVE-2025-33092: IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
nvd
CVE-2021-29678P3HIGHCVSS 8.7v9.7v10.1+3 more2021-12-09
CVE-2021-29678 [HIGH] CWE-863 CVE-2021-29678: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.
nvd
CVE-2008-1997P3CRITICALCVSS 9.0v8.0v9.1+1 more2008-04-28
CVE-2008-1997 [CRITICAL] CVE-2008-1997: Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, an
Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE-2008-0699.
nvd
CVE-2025-36384P3HIGHCVSS 7.8≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36384 [HIGH] CWE-428 CVE-2025-36384: IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate the
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.
nvd
CVE-2025-36186P3HIGHCVSS 7.8≥ 12.1.0, ≤ 12.1.32025-11-07
CVE-2025-36186 [HIGH] CWE-250 CVE-2025-36186: IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specif
IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.
nvd
CVE-2020-5025P3HIGHCVSS 7.8≥ 11.1.0.0, < 11.1.4.6≥ 11.5, < 11.5.5.0+3 more2021-03-11
CVE-2020-5025 [HIGH] CWE-120 CVE-2020-5025: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 193661.
nvd
CVE-2018-1897P3HIGHCVSS 7.8v9.7v10.1+2 more2018-11-30
CVE-2018-1897 [HIGH] CWE-787 CVE-2018-1897: IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack bas
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 152462.
nvd
CVE-2020-4701P3HIGHCVSS 7.8v10.5v11.1+1 more2020-11-19
CVE-2020-4701 [HIGH] CWE-120 CVE-2020-4701: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.
nvd
CVE-2008-6821P3CRITICALCVSS 10.0v8.0v9.1+1 more2009-06-03
CVE-2008-6821 [CRITICAL] CVE-2008-6821: Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.
nvd