Ibm Db2 vulnerabilities
340 known vulnerabilities affecting ibm/db2.
Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15
Vulnerabilities
Page 5 of 17
CVE-2023-30447P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30447 [HIGH] CWE-20 CVE-2023-30447: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253436.
nvd
CVE-2023-30446P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30446 [HIGH] CWE-20 CVE-2023-30446: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID:
253361
.
nvd
CVE-2023-30442P3HIGHCVSS 7.5v11.1.4.7v11.52023-07-10
CVE-2023-30442 [HIGH] CWE-20 CVE-2023-30442: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is vulnerable to a denial of service as the server may crash when using a specially crafted wrapper using certain options. IBM X-Force ID: 253202.
nvd
CVE-2018-1922P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1922 [HIGH] CWE-119 CVE-2018-1922: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affec
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858.
nvd
CVE-2018-1923P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1923 [HIGH] CWE-119 CVE-2018-1923: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affec
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152859.
nvd
CVE-2019-4015P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2019-4015 [HIGH] CWE-120 CVE-2019-4015: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155893.
nvd
CVE-2019-4016P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2019-4016 [HIGH] CWE-120 CVE-2019-4016: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155894.
nvd
CVE-2018-1980P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1980 [HIGH] CWE-119 CVE-2018-1980: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078.
nvd
CVE-2018-1978P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1978 [HIGH] CWE-119 CVE-2018-1978: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069.
nvd
CVE-2019-4014P3HIGHCVSS 7.8v9.7.0.0v9.7.0.1+37 more2019-04-03
CVE-2019-4014 [HIGH] CWE-120 CVE-2019-4014: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.
nvd
CVE-2018-1834P3HIGHCVSS 7.8v9.7v10.1+2 more2018-11-09
CVE-2018-1834 [HIGH] CWE-59 CVE-2018-1834: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.
nvd
CVE-2018-1802P3HIGHCVSS 7.8v9.7v10.1+2 more2018-11-09
CVE-2018-1802 [HIGH] CWE-426 CVE-2018-1802: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 149640.
nvd
CVE-2023-38727P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2023-12-04
CVE-2023-38727 [HIGH] CWE-20 CVE-2023-38727: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted SQL statement. IBM X-Force ID: 262257.
nvd
CVE-2023-40373P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.8v10.5+1 more2023-10-17
CVE-2023-40373 [HIGH] CWE-20 CVE-2023-40373: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common table expressions. IBM X-Force ID: 263574.
nvd
CVE-2023-38740P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.82023-10-16
CVE-2023-38740 [HIGH] CWE-20 CVE-2023-38740: IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of
IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted SQL statement. IBM X-Force ID: 262613.
nvd
CVE-2025-36071P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.22025-07-29
CVE-2025-36071 [HIGH] CWE-772 CVE-2025-36071: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query due to improper release of memory resources.
nvd
CVE-2025-2533P3HIGHCVSS 7.5v12.1.0v12.1.1+1 more2025-07-29
CVE-2025-2533 [HIGH] CWE-789 CVE-2025-2533: IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-36010P3HIGHCVSS 7.5v12.1.0v12.1.1+1 more2025-07-29
CVE-2025-36010 [HIGH] CWE-833 CVE-2025-36010: IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
could allow an unauthenticated user to cause a denial of service due to executable segments that are waiting for each other to release a necessary lock.
nvd
CVE-2007-3676P3CRITICALCVSS 10.0≤ 8.0≤ 9.02008-02-13
CVE-2007-3676 [CRITICAL] CWE-399 CVE-2007-3676: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix P
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: th
nvd
CVE-2018-1710P3HIGHCVSS 7.8v10.1v10.5+1 more2018-09-21
CVE-2018-1710 [HIGH] CWE-119 CVE-2018-1710: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.
nvd