cbcvebase.

Ibm Db2 vulnerabilities

353 known vulnerabilities affecting ibm/db2.

Total CVEs
353
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH148MEDIUM173LOW16

Vulnerabilities

Page 8 of 18
CVE-2017-1452P3HIGHCVSS 7.8v9.7v9.7.0.1+25 more2017-09-12
CVE-2017-1452 [HIGH] CVE-2017-1452: IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could al IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.
nvd
CVE-2024-52903P3HIGHCVSS 7.5≥ 12.1.0, ≤ 12.1.12025-05-01
CVE-2024-52903 [HIGH] CWE-248 CVE-2024-52903: IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the se IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.
nvd
CVE-2018-1857P3MEDIUMCVSS 6.5v11.12018-11-09
CVE-2018-1857 [MEDIUM] CWE-200 CVE-2018-1857: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see. IBM X-Force ID: 151155.
nvd
CVE-2008-1998P4HIGHCVSS 8.5v8.0v9.1+1 more2008-04-28
CVE-2008-1998 [HIGH] CWE-264 CVE-2008-1998: The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.
nvd
CVE-2025-2669P3MEDIUMCVSS 6.5≥ 4.8, < 5.42026-06-22
CVE-2025-2669 [MEDIUM] CWE-295 CVE-2025-2669: IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5 IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.
nvd
CVE-2025-36006P3MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0, ≤ 11.1.4.7+3 more2025-11-07
CVE-2025-36006 [MEDIUM] CWE-404 CVE-2025-36006: IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 1 IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial due to the improper release of resources after use.
nvd
CVE-2008-6820P4CRITICALCVSS 10.0v8.0v9.1+1 more2009-06-03
CVE-2008-6820 [CRITICAL] CVE-2008-6820: The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.
nvd
CVE-2010-3194P4HIGHCVSS 7.5v9.1v9.5+1 more2010-08-31
CVE-2010-3194 [HIGH] CWE-264 CVE-2010-3194: The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers t The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
nvd
CVE-2023-29256P4MEDIUMCVSS 6.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-29256 [MEDIUM] CWE-269 CVE-2023-29256: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used. IBM X-Force ID: 252046.
nvd
CVE-2023-38729P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-04-03
CVE-2023-38729 [MEDIUM] CWE-200 CVE-2023-38729: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.
nvd
CVE-2025-36001P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36001 [MEDIUM] CWE-674 CVE-2025-36001: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.
nvd
CVE-2025-36425P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-02-17
CVE-2025-36425 [MEDIUM] CWE-256 CVE-2025-36425: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.
nvd
CVE-2010-3193P4CRITICALCVSS 10.0v9.1v9.5+1 more2010-08-31
CVE-2010-3193 [CRITICAL] CVE-2010-3193: Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.
nvd
CVE-2019-4386P4MEDIUMCVSS 6.5≥ 11.1.3, ≤ 11.1.3.3≥ 11.1.4, ≤ 11.1.4.42019-07-01
CVE-2019-4386 [MEDIUM] CWE-749 CVE-2019-4386: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714.
nvd
CVE-2021-38931P4MEDIUMCVSS 6.5v11.1v11.52021-12-09
CVE-2021-38931 [MEDIUM] CWE-668 CVE-2021-38931: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
nvd
CVE-2021-20579P4MEDIUMCVSS 6.5v9.7v10.1+3 more2021-06-24
CVE-2021-20579 [MEDIUM] CVE-2021-20579: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.
nvd
CVE-2022-22483P4MEDIUMCVSS 6.5v9.7.0.0v10.1+3 more2022-09-13
CVE-2022-22483 [MEDIUM] CWE-269 CVE-2022-22483: IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
nvd
CVE-2023-35012P4MEDIUMCVSS 6.7v11.52023-07-17
CVE-2023-35012 [MEDIUM] CWE-121 CVE-2023-35012: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuratio IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with SYSADM privileges could overflow the buffer and execute arbitrary code on the system. IBM X-Force ID: 257763.
nvd
CVE-2024-31882P4MEDIUMCVSS 6.5≥ 11.1.4, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.92024-08-14
CVE-2024-31882 [MEDIUM] CWE-943 CVE-2024-31882: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a d IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287614.
nvd
CVE-2009-3473P4CRITICALCVSS 10.0v9.12009-09-29
CVE-2009-3473 [CRITICAL] CVE-2009-3473: IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATI IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
nvd
Ibm Db2 vulnerabilities | cvebase