cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 3 of 17
CVE-2020-4739P3HIGHCVSS 7.8≥ 11.5, < 11.5.5.0v9.7.0.0+3 more2020-11-20
CVE-2020-4739 [HIGH] CWE-426 CVE-2020-4739: IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a
nvd
CVE-2023-47145P3HIGHCVSS 7.8≥ 10.5, < 10.5.0.11≥ 11.1, < 11.1.4.7+2 more2024-01-07
CVE-2023-47145 [HIGH] CWE-269 CVE-2023-47145: IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to e IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.
nvd
CVE-2021-39002P3HIGHCVSS 7.5v9.7v10.1+3 more2021-12-09
CVE-2021-39002 [HIGH] CWE-327 CVE-2021-39002: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 us IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2022-43927P3HIGHCVSS 7.5v10.5v11.1+1 more2023-02-17
CVE-2022-43927 [HIGH] CWE-200 CVE-2022-43927: IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.
nvd
CVE-2023-47152P3HIGHCVSS 7.5fixed in 11.5.92024-01-22
CVE-2023-47152 [HIGH] CWE-209 CVE-2023-47152: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.
nvd
CVE-2025-36442P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36442 [HIGH] CWE-943 CVE-2025-36442: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.
nvd
CVE-2023-38003P3HIGHCVSS 7.2v10.5v11.1+1 more2023-12-04
CVE-2023-38003 [HIGH] CVE-2023-38003: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a user with DATAACCESS privileges to execute routines that they should not have access to. IBM X-Force ID: 260214.
nvd
CVE-2024-47118P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+3 more2025-11-07
CVE-2024-47118 [HIGH] CWE-121 CVE-2024-47118: IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 1 IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2015-1935P3HIGHCVSS 8.0v9.7v9.8+2 more2015-07-20
CVE-2015-1935 [HIGH] CWE-17 CVE-2015-1935: The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, an The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.
nvd
CVE-2020-4420P3HIGHCVSS 7.5v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4420 [HIGH] CWE-404 CVE-2020-4420: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the execution of a terminate command. IBM X-Force ID: 180076.
nvd
CVE-2020-5024P3HIGHCVSS 7.5≥ 11.1.0.0, < 11.1.4.6≥ 11.5, < 11.5.5.0+3 more2021-03-11
CVE-2020-5024 [HIGH] CVE-2020-5024: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the SSL handshake response. IBM X-Force ID: 193660.
nvd
CVE-2021-29703P3HIGHCVSS 7.5v9.7v10.1+3 more2021-06-24
CVE-2021-29703 [HIGH] CVE-2021-29703: Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service a Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.
nvd
CVE-2021-29825P3HIGHCVSS 7.5v11.1v11.52021-09-16
CVE-2021-29825 [HIGH] CVE-2021-29825: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive informati IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.
nvd
CVE-2021-20373P3HIGHCVSS 7.5v9.7v10.1+3 more2021-12-09
CVE-2021-20373 [HIGH] CVE-2021-20373: IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using th IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
nvd
CVE-2019-4154P3HIGHCVSS 7.8v9.7.0.0v9.7.0.1+33 more2019-07-01
CVE-2019-4154 [HIGH] CWE-119 CVE-2019-4154: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 158519.
nvd
CVE-2019-4322P3HIGHCVSS 7.8v9.7v10.1+2 more2019-07-01
CVE-2019-4322 [HIGH] CWE-119 CVE-2019-4322: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 161202.
nvd
CVE-2019-4094P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-21
CVE-2019-4094 [HIGH] CWE-427 CVE-2019-4094: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.
nvd
CVE-2023-27558P3HIGHCVSS 7.8v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-27558 [HIGH] CWE-269 CVE-2023-27558: IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at lea IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service. IBM X-Force ID: 249194.
nvd
CVE-2022-22390P3HIGHCVSS 7.5v9.7v10.1+3 more2022-06-24
CVE-2022-22390 [HIGH] CWE-269 CVE-2022-22390: IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an informat IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.
nvd
CVE-2023-40372P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.82023-10-17
CVE-2023-40372 [HIGH] CWE-20 CVE-2023-40372: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of se IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement using External Tables. IBM X-Force ID: 263499.
nvd
Ibm Db2 vulnerabilities | cvebase