cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 8 of 17
CVE-2023-29256P4MEDIUMCVSS 6.5v10.5.0.11v11.1.4.7+1 more2023-07-10
CVE-2023-29256 [MEDIUM] CWE-269 CVE-2023-29256: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper privilege management when certain federation features are used. IBM X-Force ID: 252046.
nvd
CVE-2023-38729P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-04-03
CVE-2023-38729 [MEDIUM] CWE-200 CVE-2023-38729: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.
nvd
CVE-2025-36001P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36001 [MEDIUM] CWE-674 CVE-2025-36001: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1. IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.
nvd
CVE-2025-2669P4MEDIUMCVSS 6.5≥ 4.8, < 5.42026-06-22
CVE-2025-2669 [MEDIUM] CWE-295 CVE-2025-2669: IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5 IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.
nvd
CVE-2025-36425P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-02-17
CVE-2025-36425 [MEDIUM] CWE-256 CVE-2025-36425: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 t IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.
nvd
CVE-2010-3193P4CRITICALCVSS 10.0v9.1v9.5+1 more2010-08-31
CVE-2010-3193 [CRITICAL] CVE-2010-3193: Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.
nvd
CVE-2009-3473P4CRITICALCVSS 10.0v9.12009-09-29
CVE-2009-3473 [CRITICAL] CVE-2009-3473: IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATI IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
nvd
CVE-2019-4386P4MEDIUMCVSS 6.5≥ 11.1.3, ≤ 11.1.3.3≥ 11.1.4, ≤ 11.1.4.42019-07-01
CVE-2019-4386 [MEDIUM] CWE-749 CVE-2019-4386: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714.
nvd
CVE-2021-38931P4MEDIUMCVSS 6.5v11.1v11.52021-12-09
CVE-2021-38931 [MEDIUM] CWE-668 CVE-2021-38931: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
nvd
CVE-2021-20579P4MEDIUMCVSS 6.5v9.7v10.1+3 more2021-06-24
CVE-2021-20579 [MEDIUM] CVE-2021-20579: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 co IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.
nvd
CVE-2022-22483P4MEDIUMCVSS 6.5v9.7.0.0v10.1+3 more2022-09-13
CVE-2022-22483 [MEDIUM] CWE-269 CVE-2022-22483: IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
nvd
CVE-2023-35012P4MEDIUMCVSS 6.7v11.52023-07-17
CVE-2023-35012 [MEDIUM] CWE-121 CVE-2023-35012: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuratio IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 with a Federated configuration is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with SYSADM privileges could overflow the buffer and execute arbitrary code on the system. IBM X-Force ID: 257763.
nvd
CVE-2024-31882P4MEDIUMCVSS 6.5≥ 11.1.4, ≤ 11.1.4.7≥ 11.5.0, ≤ 11.5.92024-08-14
CVE-2024-31882 [MEDIUM] CWE-943 CVE-2024-31882: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a d IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287614.
nvd
CVE-2020-4200P4MEDIUMCVSS 6.5v10.5v11.1+1 more2020-02-19
CVE-2020-4200 [MEDIUM] CVE-2020-4200: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow a IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafted commands to cause a denial of service. IBM X-Force ID: 174914.
nvd
CVE-2022-22389P4MEDIUMCVSS 6.5v9.7v10.1+3 more2022-06-24
CVE-2022-22389 [MEDIUM] CWE-89 CVE-2022-22389: IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of ser IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740.
nvd
CVE-2021-29777P4MEDIUMCVSS 6.5v9.7v10.1+3 more2021-06-24
CVE-2021-29777 [MEDIUM] CWE-829 CVE-2021-29777: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, u IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.
nvd
CVE-2019-4057P4MEDIUMCVSS 6.7v9.7.0.0v9.7.0.1+33 more2019-07-01
CVE-2019-4057 [MEDIUM] CVE-2019-4057: IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could al IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567.
nvd
CVE-2023-47746P4MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2024-01-22
CVE-2023-47746 [MEDIUM] CWE-20 CVE-2023-47746: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 272644.
nvd
CVE-2023-47158P4MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2024-01-22
CVE-2023-47158 [MEDIUM] CWE-20 CVE-2023-47158: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allo IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750.
nvd
CVE-2024-27254P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-04-03
CVE-2024-27254 [MEDIUM] CWE-20 CVE-2024-27254: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated ser IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813.
nvd
Ibm Db2 vulnerabilities | cvebase