cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 3 of 18
CVE-2020-4945P3HIGHCVSS 8.1v11.52021-06-24
CVE-2020-4945 [HIGH] CWE-732 CVE-2020-4945: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
nvd
CVE-2021-20373P3HIGHCVSS 7.5v9.7v10.1+3 more2021-12-09
CVE-2021-20373 [HIGH] CVE-2021-20373: IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using th IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
nvd
CVE-2017-1677P3HIGHCVSS 7.8v9.7v10.1+2 more2018-03-22
CVE-2017-1677 [HIGH] CWE-502 CVE-2017-1677: IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 1 IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.
nvd
CVE-2020-4204P3HIGHCVSS 7.8v9.7v10.1+3 more2020-02-19
CVE-2020-4204 [HIGH] CWE-120 CVE-2020-4204: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 174960.
nvd
CVE-2018-1936P3HIGHCVSS 7.8v9.7.0.0v9.7.0.1+37 more2019-04-03
CVE-2018-1936 [HIGH] CWE-787 CVE-2018-1936: IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, cause IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.
nvd
CVE-2018-1459P3HIGHCVSS 7.8v9.7v10.1+2 more2018-05-25
CVE-2018-1459 [HIGH] CWE-787 CVE-2018-1459: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based buffer overflow, caused by improper bounds checking which could lead an attacker to execute arbitrary code. IBM X-Force ID: 140210.
nvd
CVE-2020-4363P3HIGHCVSS 7.8v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4363 [HIGH] CWE-120 CVE-2020-4363: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 178960.
nvd
CVE-2020-4739P3HIGHCVSS 7.8≥ 11.5, < 11.5.5.0v9.7.0.0+3 more2020-11-20
CVE-2020-4739 [HIGH] CWE-426 CVE-2020-4739: IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a
nvd
CVE-2023-30431P3HIGHCVSS 7.8v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30431 [HIGH] CWE-119 CVE-2023-30431: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vul IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow the buffer and execute arbitrary code. IBM X-Force ID: 252184.
nvd
CVE-2021-39002P3HIGHCVSS 7.5v9.7v10.1+3 more2021-12-09
CVE-2021-39002 [HIGH] CWE-327 CVE-2021-39002: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 us IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2022-43927P3HIGHCVSS 7.5v10.5v11.1+1 more2023-02-17
CVE-2022-43927 [HIGH] CWE-200 CVE-2022-43927: IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671.
nvd
CVE-2023-47152P3HIGHCVSS 7.5fixed in 11.5.92024-01-22
CVE-2023-47152 [HIGH] CWE-209 CVE-2023-47152: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions.
nvd
CVE-2025-36442P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36442 [HIGH] CWE-943 CVE-2025-36442: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.
nvd
CVE-2026-6052P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-6052 [HIGH] CWE-400 CVE-2026-6052: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.
nvd
CVE-2023-38003P3HIGHCVSS 7.2v10.5v11.1+1 more2023-12-04
CVE-2023-38003 [HIGH] CVE-2023-38003: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a user with DATAACCESS privileges to execute routines that they should not have access to. IBM X-Force ID: 260214.
nvd
CVE-2026-6051P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-6051 [HIGH] CWE-400 CVE-2026-6051: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when e IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.
nvd
CVE-2015-1935P3HIGHCVSS 8.0v9.7v9.8+2 more2015-07-20
CVE-2015-1935 [HIGH] CWE-17 CVE-2015-1935: The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, an The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.
nvd
CVE-2012-2197P3HIGHCVSS 7.1v9.1v9.1.0.1+32 more2012-07-25
CVE-2012-2197 [HIGH] CWE-119 CVE-2012-2197: Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.
nvd
CVE-2020-4420P3HIGHCVSS 7.5v9.7.0.0v10.1.0.0+3 more2020-07-01
CVE-2020-4420 [HIGH] CWE-404 CVE-2020-4420: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the execution of a terminate command. IBM X-Force ID: 180076.
nvd
CVE-2020-5024P3HIGHCVSS 7.5≥ 11.1.0.0, < 11.1.4.6≥ 11.5, < 11.5.5.0+3 more2021-03-11
CVE-2020-5024 [HIGH] CVE-2020-5024: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the SSL handshake response. IBM X-Force ID: 193660.
nvd
Ibm Db2 vulnerabilities | cvebase