cbcvebase.

Ibm Db2 vulnerabilities

340 known vulnerabilities affecting ibm/db2.

Total CVEs
340
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH143MEDIUM168LOW15

Vulnerabilities

Page 9 of 17
CVE-2024-25046P4MEDIUMCVSS 6.5v11.1v11.52024-04-03
CVE-2024-25046 [MEDIUM] CWE-20 CVE-2024-25046: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a d IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query. IBM X-Force ID: 282953.
nvd
CVE-2023-29267P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-06-12
CVE-2023-29267 [MEDIUM] CWE-399 CVE-2023-29267: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287612.
nvd
CVE-2024-35136P4MEDIUMCVSS 6.5≥ 10.5.0, ≤ 10.5.11≥ 11.1.4, ≤ 11.1.4.7+1 more2024-08-14
CVE-2024-35136 [MEDIUM] CWE-943 CVE-2024-35136: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 1 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions. IBM X-Force ID: 291307.
nvd
CVE-2024-54178P4MEDIUMCVSS 6.5≥ 4.8, < 5.42026-06-22
CVE-2024-54178 [MEDIUM] CWE-770 CVE-2024-54178: IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 c IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.
nvd
CVE-2026-1577P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-04-30
CVE-2026-1577 [MEDIUM] CWE-1284 CVE-2026-1577: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
nvd
CVE-2026-1352P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-04-23
CVE-2026-1352 [MEDIUM] CWE-1284 CVE-2026-1352: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
nvd
CVE-2025-36424P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-01-30
CVE-2025-36424 [MEDIUM] CWE-1284 CVE-2025-36424: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a deni IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to improper neutralization of special elements in data query logic.
nvd
CVE-2026-11906P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.42026-06-30
CVE-2026-11906 [MEDIUM] CWE-1284 CVE-2026-11906: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns.
nvd
CVE-2025-36122P4MEDIUMCVSS 6.5≥ 11.5.0, ≤ 11.5.9≥ 12.1.0, ≤ 12.1.32026-04-30
CVE-2025-36122 [MEDIUM] CWE-770 CVE-2025-36122: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 C IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.
nvd
CVE-2009-3471P4HIGHCVSS 7.5v8.0v9.1+1 more2009-09-29
CVE-2009-3471 [HIGH] CVE-2009-3471: IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expec IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
nvd
CVE-2008-4692P4CRITICALCVSS 10.0≤ 8.0≤ 9.1+4 more2008-10-22
CVE-2008-4692 [CRITICAL] CVE-2008-4692: The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 bef The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.
nvd
CVE-2016-5995P4HIGHCVSS 7.3v9.7v9.7.0.1+25 more2016-10-01
CVE-2016-5995 [HIGH] CWE-264 CVE-2016-5995: Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.
nvd
CVE-2018-1977P4MEDIUMCVSS 6.5v11.12018-12-14
CVE-2018-1977 [MEDIUM] CWE-20 CVE-2018-1977: IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with TRUNCATE function. IBM X-Force ID: 154032.
nvd
CVE-2022-35637P4MEDIUMCVSS 6.5v10.5v11.1+1 more2022-09-13
CVE-2022-35637 [MEDIUM] CVE-2022-35637: IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of ser IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.
nvd
CVE-2023-47747P4MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.0.11≥ 11.1.0.0, ≤ 11.1.4.7+1 more2024-01-22
CVE-2023-47747 [MEDIUM] CWE-20 CVE-2023-47747: IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow a IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 272646.
nvd
CVE-2023-47141P4MEDIUMCVSS 6.5fixed in 11.5.92024-01-22
CVE-2023-47141 [MEDIUM] CWE-20 CVE-2023-47141: IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270264.
nvd
CVE-2024-22360P4MEDIUMCVSS 6.5v11.52024-04-03
CVE-2024-22360 [MEDIUM] CWE-20 CVE-2024-22360: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables. IBM X-Force ID: 280905.
nvd
CVE-2024-31881P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-06-12
CVE-2024-31881 [MEDIUM] CWE-770 CVE-2024-31881: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user. IBM X-Force ID: 287613.
nvd
CVE-2024-28762P4MEDIUMCVSS 6.5v10.5v11.1+1 more2024-06-12
CVE-2024-28762 [MEDIUM] CWE-770 CVE-2024-28762: IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 285246.
nvd
CVE-2024-31880P4MEDIUMCVSS 6.5≥ 10.5.0.0, ≤ 10.5.11≥ 11.1.4, ≤ 11.1.4.7+1 more2024-10-23
CVE-2024-31880 [MEDIUM] CWE-770 CVE-2024-31880: IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.
nvd
Ibm Db2 vulnerabilities | cvebase