Ibm Db2 vulnerabilities
353 known vulnerabilities affecting ibm/db2.
Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16
Vulnerabilities
Page 7 of 18
CVE-2024-49350P3HIGHCVSS 7.5≥ 11.1, ≤ 11.1.4.7≥ 11.5, ≤ 11.5.9+1 more2025-05-29
CVE-2024-49350 [HIGH] CWE-121 CVE-2024-49350: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 th
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-2518P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.12025-05-29
CVE-2025-2518 [HIGH] CWE-789 CVE-2025-2518: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1
is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-2533P3HIGHCVSS 7.5v12.1.0v12.1.1+1 more2025-07-29
CVE-2025-2533 [HIGH] CWE-789 CVE-2025-2533: IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-36071P3HIGHCVSS 7.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.22025-07-29
CVE-2025-36071 [HIGH] CWE-772 CVE-2025-36071: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query due to improper release of memory resources.
nvd
CVE-2025-36010P3HIGHCVSS 7.5v12.1.0v12.1.1+1 more2025-07-29
CVE-2025-36010 [HIGH] CWE-833 CVE-2025-36010: IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
could allow an unauthenticated user to cause a denial of service due to executable segments that are waiting for each other to release a necessary lock.
nvd
CVE-2025-36372P3MEDIUMCVSS 6.5≥ 11.5.0, < 11.5.9≥ 12.1.0, ≤ 12.1.4+1 more2026-06-30
CVE-2025-36372 [MEDIUM] CWE-538 CVE-2025-36372: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 C
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.
nvd
CVE-2017-1451P3HIGHCVSS 7.8v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1451 [HIGH] CVE-2017-1451: IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could al
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.
nvd
CVE-2023-45178P3HIGHCVSS 7.5v11.52023-12-03
CVE-2023-45178 [HIGH] CWE-20 CVE-2023-45178: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 CLI is vulnerable to a denial of service when a specially crafted request is used. IBM X-Force ID: 268073.
nvd
CVE-2023-40692P3HIGHCVSS 7.5v10.5v11.1+1 more2023-12-04
CVE-2023-40692 [HIGH] CWE-400 CVE-2023-40692: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to denial of service under extreme stress conditions. IBM X-Force ID: 264807.
nvd
CVE-2019-4588P3HIGHCVSS 7.8v9.7v10.1+3 more2021-05-26
CVE-2019-4588 [HIGH] CWE-427 CVE-2019-4588: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.
nvd
CVE-2023-26021P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+1 more2023-04-28
CVE-2023-26021 [HIGH] CWE-20 CVE-2023-26021: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a d
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause. IBM X-Force ID: 247864.
nvd
CVE-2023-29255P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-27
CVE-2023-29255 [HIGH] CWE-20 CVE-2023-29255: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.
nvd
CVE-2023-26022P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-28
CVE-2023-26022 [HIGH] CWE-20 CVE-2023-26022: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of servi
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory occurs using the DBMS_OUTPUT module. IBM X-Force ID: 247868.
nvd
CVE-2023-27559P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-26
CVE-2023-27559 [HIGH] CWE-20 CVE-2023-27559: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted subquery. IBM X-Force ID: 249196.
nvd
CVE-2023-30991P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.8v11.1.42023-10-16
CVE-2023-30991 [HIGH] CWE-20 CVE-2023-30991: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to den
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 254037.
nvd
CVE-2023-30987P3HIGHCVSS 7.5≥ 11.5, < 11.5.8v10.5+1 more2023-10-16
CVE-2023-30987 [HIGH] CWE-20 CVE-2023-30987: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain databases. IBM X-Force ID: 253440.
nvd
CVE-2023-40374P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.82023-10-16
CVE-2023-40374 [HIGH] CWE-20 CVE-2023-40374: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of se
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted query statement. IBM X-Force ID: 263575.
nvd
CVE-2022-43929P3HIGHCVSS 7.5v11.1v11.52023-02-17
CVE-2022-43929 [HIGH] CWE-20 CVE-2022-43929: IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when exe
IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-Force ID: 241676.
nvd
CVE-2023-27555P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-28
CVE-2023-27555 [HIGH] CWE-20 CVE-2023-27555: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinity for unfenced DRDA federation wrappers. IBM X-Force ID: 249187.
nvd
CVE-2009-4333P3HIGHCVSS 7.5v9.52009-12-16
CVE-2009-4333 [HIGH] CWE-200 CVE-2009-4333: The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the pass
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
nvd