cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 5 of 18
CVE-2018-1802P3HIGHCVSS 7.8v9.7v10.1+2 more2018-11-09
CVE-2018-1802 [HIGH] CWE-426 CVE-2018-1802: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 149640.
nvd
CVE-2019-4094P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-21
CVE-2019-4094 [HIGH] CWE-427 CVE-2019-4094: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.
nvd
CVE-2023-38727P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2023-12-04
CVE-2023-38727 [HIGH] CWE-20 CVE-2023-38727: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted SQL statement. IBM X-Force ID: 262257.
nvd
CVE-2023-40373P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.8v10.5+1 more2023-10-17
CVE-2023-40373 [HIGH] CWE-20 CVE-2023-40373: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common table expressions. IBM X-Force ID: 263574.
nvd
CVE-2023-40372P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.82023-10-17
CVE-2023-40372 [HIGH] CWE-20 CVE-2023-40372: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of se IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement using External Tables. IBM X-Force ID: 263499.
nvd
CVE-2023-38740P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.82023-10-16
CVE-2023-38740 [HIGH] CWE-20 CVE-2023-38740: IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted SQL statement. IBM X-Force ID: 262613.
nvd
CVE-2024-51473P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+2 more2025-07-29
CVE-2024-51473 [HIGH] CWE-121 CVE-2024-51473: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2024-49828P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+2 more2025-07-29
CVE-2024-49828 [HIGH] CWE-121 CVE-2024-49828: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-2534P3HIGHCVSS 7.5≥ 11.1.0, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.9+1 more2025-11-07
CVE-2025-2534 [HIGH] CWE-789 CVE-2025-2534: IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX an IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2007-3676P3CRITICALCVSS 10.0≤ 8.0≤ 9.02008-02-13
CVE-2007-3676 [CRITICAL] CWE-399 CVE-2007-3676: IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix P IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: th
nvd
CVE-2023-27859P3MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2024-01-22
CVE-2023-27859 [MEDIUM] CWE-427 CVE-2023-27859: IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installin IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.
nvd
CVE-2023-30449P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30449 [HIGH] CWE-20 CVE-2023-30449: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439.
nvd
CVE-2023-30445P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30445 [HIGH] CWE-20 CVE-2023-30445: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.
nvd
CVE-2023-30448P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30448 [HIGH] CWE-20 CVE-2023-30448: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437.
nvd
CVE-2023-30447P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30447 [HIGH] CWE-20 CVE-2023-30447: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253436.
nvd
CVE-2023-30446P3HIGHCVSS 7.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-30446 [HIGH] CWE-20 CVE-2023-30446: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253361 .
nvd
CVE-2023-30442P3HIGHCVSS 7.5v11.1.4.7v11.52023-07-10
CVE-2023-30442 [HIGH] CWE-20 CVE-2023-30442: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is vulnerable to a denial of service as the server may crash when using a specially crafted wrapper using certain options. IBM X-Force ID: 253202.
nvd
CVE-2018-1922P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1922 [HIGH] CWE-119 CVE-2018-1922: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affec IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858.
nvd
CVE-2018-1710P3HIGHCVSS 7.8v10.1v10.5+1 more2018-09-21
CVE-2018-1710 [HIGH] CWE-119 CVE-2018-1710: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.
nvd
CVE-2018-1923P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1923 [HIGH] CWE-119 CVE-2018-1923: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affec IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152859.
nvd
Ibm Db2 vulnerabilities | cvebase