Ibm Db2 vulnerabilities
340 known vulnerabilities affecting ibm/db2.
Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15
Vulnerabilities
Page 7 of 17
CVE-2024-45663P3HIGHCVSS 7.5≥ 11.1.4, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.9+1 more2024-11-21
CVE-2024-45663 [HIGH] CVE-2024-45663: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2024-49350P3HIGHCVSS 7.5≥ 11.1, ≤ 11.1.4.7≥ 11.5, ≤ 11.5.9+1 more2025-05-29
CVE-2024-49350 [HIGH] CWE-121 CVE-2024-49350: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 th
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-2518P3HIGHCVSS 7.5≥ 11.5, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.12025-05-29
CVE-2025-2518 [HIGH] CWE-789 CVE-2025-2518: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1
is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2017-1451P3HIGHCVSS 7.8v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1451 [HIGH] CVE-2017-1451: IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could al
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.
nvd
CVE-2019-4588P3HIGHCVSS 7.8v9.7v10.1+3 more2021-05-26
CVE-2019-4588 [HIGH] CWE-427 CVE-2019-4588: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.
nvd
CVE-2023-26021P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+1 more2023-04-28
CVE-2023-26021 [HIGH] CWE-20 CVE-2023-26021: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a d
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause. IBM X-Force ID: 247864.
nvd
CVE-2023-29255P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-27
CVE-2023-29255 [HIGH] CWE-20 CVE-2023-29255: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.
nvd
CVE-2023-26022P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-28
CVE-2023-26022 [HIGH] CWE-20 CVE-2023-26022: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of servi
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash when an Out of Memory occurs using the DBMS_OUTPUT module. IBM X-Force ID: 247868.
nvd
CVE-2023-27559P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-26
CVE-2023-27559 [HIGH] CWE-20 CVE-2023-27559: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted subquery. IBM X-Force ID: 249196.
nvd
CVE-2022-43929P3HIGHCVSS 7.5v11.1v11.52023-02-17
CVE-2022-43929 [HIGH] CWE-20 CVE-2022-43929: IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when exe
IBM Db2 for Linux, UNIX and Windows 11.1 and 11.5 may be vulnerable to a Denial of Service when executing a specially crafted 'Load' command. IBM X-Force ID: 241676.
nvd
CVE-2023-27555P3HIGHCVSS 7.5≥ 11.1, < 11.1.4≥ 11.5, < 11.5.8+2 more2023-04-28
CVE-2023-27555 [HIGH] CWE-20 CVE-2023-27555: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinity for unfenced DRDA federation wrappers. IBM X-Force ID: 249187.
nvd
CVE-2024-52903P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.12025-05-01
CVE-2024-52903 [HIGH] CWE-248 CVE-2024-52903: IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the se
IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2025-36006P3MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+3 more2025-11-07
CVE-2025-36006 [MEDIUM] CWE-404 CVE-2025-36006: IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 1
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial due to the improper release of resources after use.
nvd
CVE-2025-36372P3MEDIUMCVSS 6.5≥ 11.5.0, < 11.5.9≥ 12.1.0, ≤ 12.1.4+1 more2026-06-30
CVE-2025-36372 [MEDIUM] CWE-538 CVE-2025-36372: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 C
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables.
nvd
CVE-2008-6820P4CRITICALCVSS 10.0v8.0v9.1+1 more2009-06-03
CVE-2008-6820 [CRITICAL] CVE-2008-6820: The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
nvd
CVE-2009-4333P3HIGHCVSS 7.5v9.52009-12-16
CVE-2009-4333 [HIGH] CWE-200 CVE-2009-4333: The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the pass
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
nvd
CVE-2017-1452P3HIGHCVSS 7.8v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1452 [HIGH] CVE-2017-1452: IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could al
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.
nvd
CVE-2018-1857P3MEDIUMCVSS 6.5v11.12018-11-09
CVE-2018-1857 [MEDIUM] CWE-200 CVE-2018-1857: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see. IBM X-Force ID: 151155.
nvd
CVE-2008-1998P4HIGHCVSS 8.5v8.0v9.1+1 more2008-04-28
CVE-2008-1998 [HIGH] CWE-264 CVE-2008-1998: The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before
The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
nvd
CVE-2010-3194P4HIGHCVSS 7.5v9.1v9.5+1 more2010-08-31
CVE-2010-3194 [HIGH] CWE-264 CVE-2010-3194: The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers t
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
nvd