Ibm Db2 High Performance Unload Load vulnerabilities

8 known vulnerabilities affecting ibm/db2_high_performance_unload_load.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2025-33131MEDIUMCVSS 6.5≥ 5.1.0.0, ≤ 6.1.0.0v6.1.0.1+3 more2025-10-28
CVE-2025-33131 [MEDIUM] CWE-120 CVE-2025-33131: IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 c IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.
nvd
CVE-2025-33126MEDIUMCVSS 6.5≥ 5.1.0.0, ≤ 6.1.0.0v6.1.0.1+3 more2025-10-28
CVE-2025-33126 [MEDIUM] CWE-131 CVE-2025-33126: IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1. IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to cr
nvd
CVE-2025-33132MEDIUMCVSS 6.5≥ 5.1.0.0, ≤ 6.1.0.0v6.1.0.1+3 more2025-10-28
CVE-2025-33132 [MEDIUM] CWE-467 CVE-2025-33132: IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 c IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of the size of the data that is being pointed to.
nvd
CVE-2025-33133MEDIUMCVSS 6.5≥ 5.1.0.0, ≤ 6.1.0.0v6.1.0.1+3 more2025-10-28
CVE-2025-33133 [MEDIUM] CWE-787 CVE-2025-33133: IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 c IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due an out of bounds write.
nvd
CVE-2019-4606HIGHCVSS 7.8v5.1.0.0v5.1.0.1+5 more2019-12-12
CVE-2019-4606 [HIGH] CWE-426 CVE-2019-4606: IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arb IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 168298.
nvd
CVE-2019-4523HIGHCVSS 7.8v6.1v6.52019-10-22
CVE-2019-4523 [HIGH] CWE-120 CVE-2019-4523: IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 165481.
nvd
CVE-2019-4447HIGHCVSS 7.8v6.1v6.1.0.1+1 more2019-08-26
CVE-2019-4447 [HIGH] CWE-427 CVE-2019-4447: IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6. IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user controlled location. When a crash is induced the troj
nvd
CVE-2019-4448HIGHCVSS 7.8v6.1v6.1.0.1+1 more2019-08-26
CVE-2019-4448 [HIGH] CWE-269 CVE-2019-4448: IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6. IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authori
nvd