cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 6 of 18
CVE-2019-4015P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2019-4015 [HIGH] CWE-120 CVE-2019-4015: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155893.
nvd
CVE-2019-4016P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2019-4016 [HIGH] CWE-120 CVE-2019-4016: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155894.
nvd
CVE-2018-1980P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1980 [HIGH] CWE-119 CVE-2018-1980: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078.
nvd
CVE-2018-1978P3HIGHCVSS 7.8v9.7v10.1+2 more2019-03-11
CVE-2018-1978 [HIGH] CWE-119 CVE-2018-1978: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulne IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069.
nvd
CVE-2018-1488P3HIGHCVSS 7.8v10.5v11.12018-05-25
CVE-2018-1488 [HIGH] CWE-119 CVE-2018-1488: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a b IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.
nvd
CVE-2018-1781P3HIGHCVSS 7.8v9.7v10.1+2 more2018-11-09
CVE-2018-1781 [HIGH] CWE-59 CVE-2018-1781: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.
nvd
CVE-2018-1566P3HIGHCVSS 7.8v9.7v10.1+2 more2018-07-10
CVE-2018-1566 [HIGH] CWE-134 CVE-2018-1566: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023.
nvd
CVE-2018-1780P3HIGHCVSS 7.8v9.7v10.1+2 more2018-11-09
CVE-2018-1780 [HIGH] CWE-59 CVE-2018-1780: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148803.
nvd
CVE-2018-1487P3HIGHCVSS 7.8v9.7v10.1+2 more2018-07-10
CVE-2018-1487 [HIGH] CWE-426 CVE-2018-1487: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.
nvd
CVE-2018-1544P3HIGHCVSS 7.8v9.7v10.1+2 more2018-05-25
CVE-2018-1544 [HIGH] CWE-119 CVE-2018-1544: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 142648.
nvd
CVE-2018-1565P3HIGHCVSS 7.8v9.7v10.1+2 more2018-05-25
CVE-2018-1565 [HIGH] CWE-119 CVE-2018-1565: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 143022.
nvd
CVE-2018-1711P3HIGHCVSS 7.8v9.7v10.1+2 more2018-09-21
CVE-2018-1711 [HIGH] CWE-732 CVE-2018-1711: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369.
nvd
CVE-2023-47701P3HIGHCVSS 7.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2023-12-04
CVE-2023-47701 [HIGH] CWE-20 CVE-2023-47701: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 266166.
nvd
CVE-2023-46167P3HIGHCVSS 7.5≥ 11.5.6, ≤ 11.5.82023-12-04
CVE-2023-46167 [HIGH] CWE-20 CVE-2023-46167: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerabl IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 269367.
nvd
CVE-2023-40687P3HIGHCVSS 7.5≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2023-12-04
CVE-2023-40687 [HIGH] CWE-20 CVE-2023-40687: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted RUNSTATS command on an 8TB table. IBM X-Force ID: 264809.
nvd
CVE-2023-29258P3HIGHCVSS 7.5≥ 11.1.0.0, ≤ 11.1.4.7≥ 11.5, ≤ 11.5.92023-12-04
CVE-2023-29258 [HIGH] CWE-20 CVE-2023-29258: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service through a specially crafted federated query on specific federation objects. IBM X-Force ID: 252048.
nvd
CVE-2023-45193P3HIGHCVSS 7.5fixed in 11.5.92024-01-22
CVE-2023-45193 [HIGH] CWE-20 CVE-2023-45193: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerabl IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted cursor is used. IBM X-Force ID: 268759.
nvd
CVE-2023-38720P3HIGHCVSS 7.5≥ 11.5, < 11.5.8v11.1.42023-10-16
CVE-2023-38720 [HIGH] CWE-20 CVE-2023-38720: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to den IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with a specially crafted ALTER TABLE statement. IBM X-Force ID: 261616.
nvd
CVE-2023-38728P3HIGHCVSS 7.5≥ 11.5, < 11.5.8v10.5+1 more2023-10-16
CVE-2023-38728 [HIGH] CWE-20 CVE-2023-38728: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted XML query statement. IBM X-Force ID: 262258.
nvd
CVE-2024-45663P3HIGHCVSS 7.5≥ 11.1.4, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.9+1 more2024-11-21
CVE-2024-45663 [HIGH] CVE-2024-45663: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
Ibm Db2 vulnerabilities | cvebase