Ibm Db2 vulnerabilities
353 known vulnerabilities affecting ibm/db2.
Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16
Vulnerabilities
Page 4 of 18
CVE-2021-29703P3HIGHCVSS 7.5v9.7v10.1+3 more2021-06-24
CVE-2021-29703 [HIGH] CVE-2021-29703: Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service a
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.
nvd
CVE-2021-29825P3HIGHCVSS 7.5v11.1v11.52021-09-16
CVE-2021-29825 [HIGH] CVE-2021-29825: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive informati
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.
nvd
CVE-2019-4154P3HIGHCVSS 7.8v9.7.0.0v9.7.0.1+33 more2019-07-01
CVE-2019-4154 [HIGH] CWE-119 CVE-2019-4154: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 158519.
nvd
CVE-2019-4322P3HIGHCVSS 7.8v9.7v10.1+2 more2019-07-01
CVE-2019-4322 [HIGH] CWE-119 CVE-2019-4322: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 161202.
nvd
CVE-2023-27558P3HIGHCVSS 7.8v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-27558 [HIGH] CWE-269 CVE-2023-27558: IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at lea
IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path. A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service. IBM X-Force ID: 249194.
nvd
CVE-2022-22390P3HIGHCVSS 7.5v9.7v10.1+3 more2022-06-24
CVE-2022-22390 [HIGH] CWE-269 CVE-2022-22390: IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an informat
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.
nvd
CVE-2023-47145P3HIGHCVSS 7.8≥ 10.5, < 10.5.0.11≥ 11.1, < 11.1.4.7+2 more2024-01-07
CVE-2023-47145 [HIGH] CWE-269 CVE-2023-47145: IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to e
IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.
nvd
CVE-2022-43930P3HIGHCVSS 7.5v10.5v11.1+1 more2023-02-17
CVE-2022-43930 [HIGH] CWE-200 CVE-2022-43930: IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log file. IBM X-Force ID: 241677.
nvd
CVE-2025-36070P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36070 [HIGH] CWE-770 CVE-2025-36070: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap may occur when selecting from certain types of tables.
nvd
CVE-2026-1718P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-05-27
CVE-2026-1718 [HIGH] CWE-770 CVE-2026-1718: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
nvd
CVE-2025-33114P3HIGHCVSS 7.5v12.1.0v12.1.1+1 more2025-07-29
CVE-2025-33114 [HIGH] CWE-943 CVE-2025-33114: IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
is vulnerable to denial of service with a specially crafted query under certain non-default conditions.
nvd
CVE-2024-47118P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+3 more2025-11-07
CVE-2024-47118 [HIGH] CWE-121 CVE-2024-47118: IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 1
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2013-6744P3HIGHCVSS 8.5v9.5v9.7+16 more2014-05-30
CVE-2013-6744 [HIGH] CWE-264 CVE-2013-6744: The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 befo
The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.
nvd
CVE-2022-41296P3HIGHCVSS 8.8v3.5v4.0+1 more2022-12-12
CVE-2022-41296 [HIGH] CWE-352 CVE-2022-41296: IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.
nvd
CVE-2020-4135P3HIGHCVSS 7.5v9.7v10.1+3 more2020-02-19
CVE-2020-4135 [HIGH] CVE-2020-4135: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage.
nvd
CVE-2009-4335P3CRITICALCVSS 10.0v9.52009-12-16
CVE-2009-4335 [CRITICAL] CVE-2009-4335: Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component
Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."
nvd
CVE-2018-1458P3HIGHCVSS 7.8v9.7v10.1+2 more2018-07-10
CVE-2018-1458 [HIGH] CWE-426 CVE-2018-1458: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could all
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.
nvd
CVE-2021-29702P3HIGHCVSS 7.5≥ 11.1, ≤ 11.1.4≥ 11.5, ≤ 11.5.5.02021-06-16
CVE-2021-29702 [HIGH] CWE-74 CVE-2021-29702: Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a d
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
nvd
CVE-2019-4014P3HIGHCVSS 7.8v9.7.0.0v9.7.0.1+37 more2019-04-03
CVE-2019-4014 [HIGH] CWE-120 CVE-2019-4014: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.
nvd
CVE-2018-1834P3HIGHCVSS 7.8v9.7v10.1+2 more2018-11-09
CVE-2018-1834 [HIGH] CWE-59 CVE-2018-1834: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.
nvd