Ibm Db2 vulnerabilities
340 known vulnerabilities affecting ibm/db2.
Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15
Vulnerabilities
Page 4 of 17
CVE-2022-43930P3HIGHCVSS 7.5v10.5v11.1+1 more2023-02-17
CVE-2022-43930 [HIGH] CWE-200 CVE-2022-43930: IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677.
nvd
CVE-2026-1718P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-1718 [HIGH] CWE-770 CVE-2026-1718: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
nvd
CVE-2025-36070P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36070 [HIGH] CWE-770 CVE-2025-36070: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap may occur when selecting from certain types of tables.
nvd
CVE-2025-33114P3HIGHCVSS 7.5v12.1.0v12.1.1+1 more2025-07-29
CVE-2025-33114 [HIGH] CWE-943 CVE-2025-33114: IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
is vulnerable to denial of service with a specially crafted query under certain non-default conditions.
nvd
CVE-2024-49828P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+2 more2025-07-29
CVE-2024-49828 [HIGH] CWE-121 CVE-2024-49828: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2024-51473P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+2 more2025-07-29
CVE-2024-51473 [HIGH] CWE-121 CVE-2024-51473: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2
is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-2534P3HIGHCVSS 7.5≥ 11.1.0, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.9+1 more2025-11-07
CVE-2025-2534 [HIGH] CWE-789 CVE-2025-2534: IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX an
IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2026-6052P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-6052 [HIGH] CWE-400 CVE-2026-6052: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.
nvd
CVE-2026-6051P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-6051 [HIGH] CWE-400 CVE-2026-6051: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when e
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.
nvd
CVE-2013-6744P3HIGHCVSS 8.5v9.5v9.7+16 more2014-05-30
CVE-2013-6744 [HIGH] CWE-264 CVE-2013-6744: The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 befo
The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.
nvd
CVE-2023-27859P3MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2024-01-22
CVE-2023-27859 [MEDIUM] CWE-427 CVE-2023-27859: IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installin
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.
nvd
CVE-2022-41296P3HIGHCVSS 8.8v3.5v4.0+1 more2022-12-12
CVE-2022-41296 [HIGH] CWE-352 CVE-2022-41296: IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.
nvd
CVE-2012-2197P3HIGHCVSS 7.1v9.1v9.1.0.1+32 more2012-07-25
CVE-2012-2197 [HIGH] CWE-119 CVE-2012-2197: Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12,
Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.
nvd
CVE-2020-4135P3HIGHCVSS 7.5v9.7v10.1+3 more2020-02-19
CVE-2020-4135 [HIGH] CVE-2020-4135: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage.
nvd
CVE-2009-4335P3CRITICALCVSS 10.0v9.52009-12-16
CVE-2009-4335 [CRITICAL] CVE-2009-4335: Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component
Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."
nvd
CVE-2018-1458P3HIGHCVSS 7.8v9.7v10.1+2 more2018-07-10
CVE-2018-1458 [HIGH] CWE-426 CVE-2018-1458: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could all
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.
nvd
CVE-2021-29702P3HIGHCVSS 7.5≥ 11.1, ≤ 11.1.4≥ 11.5, ≤ 11.5.5.02021-06-16
CVE-2021-29702 [HIGH] CWE-74 CVE-2021-29702: Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a d
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
nvd
CVE-2023-30449P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30449 [HIGH] CWE-20 CVE-2023-30449: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439.
nvd
CVE-2023-30445P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30445 [HIGH] CWE-20 CVE-2023-30445: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.
nvd
CVE-2023-30448P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30448 [HIGH] CWE-20 CVE-2023-30448: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437.
nvd