Ibm Db2 Universal Database vulnerabilities
66 known vulnerabilities affecting ibm/db2_universal_database.
Total CVEs
66
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH22MEDIUM32LOW3
Vulnerabilities
Page 2 of 4
CVE-2001-0052P4LOWCVSS 2.1PoCv6.1v7.12001-02-16
CVE-2001-0052 [LOW] CVE-2001-0052: IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed que
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
nvd
CVE-2007-6045P4CRITICALCVSS 10.0≤ 9.12007-11-20
CVE-2007-6045 [CRITICAL] CVE-2007-6045: Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has u
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
nvd
CVE-2007-6048P4CRITICALCVSS 10.0≤ 9.12007-11-20
CVE-2007-6048 [CRITICAL] CWE-264 CVE-2007-6048: IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unkno
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
nvd
CVE-2010-3739P4MEDIUMCVSS 6.4≤ 9.5v9.52010-10-05
CVE-2010-3739 [MEDIUM] CWE-287 CVE-2010-3739: The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audi
The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.
nvd
CVE-2007-4417P4MEDIUMCVSS 6.0≤ 8.0≤ 9.12007-08-18
CVE-2007-4417 [MEDIUM] CVE-2007-4417: IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on method
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine auth cache is flushed.
nvd
CVE-2005-4738P4MEDIUMCVSS 6.5v8.0v8.1+10 more2005-12-31
CVE-2005-4738 [MEDIUM] CVE-2005-4738: IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execut
IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.
nvd
CVE-2007-6052P4HIGHCVSS 7.8≤ 9.12007-11-20
CVE-2007-6052 [HIGH] CVE-2007-6052: IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow atta
IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
nvd
CVE-2007-6053P4CRITICALCVSS 9.3≤ 9.12007-11-20
CVE-2007-6053 [CRITICAL] CWE-399 CVE-2007-6053: IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, w
IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
nvd
CVE-2005-4863P4HIGHCVSS 7.2v7.0v7.1+2 more2005-12-31
CVE-2005-4863 [HIGH] CWE-119 CVE-2005-4863: Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary
Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter.
nvd
CVE-2007-5758P4MEDIUMCVSS 6.9v8v9.1+1 more2008-04-16
CVE-2007-5758 [MEDIUM] CWE-119 CVE-2007-5758: Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal
Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
nvd
CVE-2005-0417P4CRITICALCVSS 10.0v6.0v7.0+5 more2005-04-27
CVE-2005-0417 [CRITICAL] CVE-2005-0417: Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and a
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor.
nvd
CVE-2007-4276P4MEDIUMCVSS 6.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4276 [MEDIUM] CWE-119 CVE-2007-4276: Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attacke
Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.
nvd
CVE-2005-4737P4HIGHCVSS 7.5v8.0v8.1+10 more2005-12-31
CVE-2005-4737 [HIGH] CVE-2005-4737: IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to c
IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by "abnormally" terminating a connection, which prevents db2agents from being properly cleared.
nvd
CVE-2007-1089P4HIGHCVSS 7.2≤ 9.1v9.12007-02-23
CVE-2007-1089 [HIGH] CVE-2007-1089: IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privile
IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.
nvd
CVE-2007-4423P4MEDIUMCVSS 5.0v8.0v9.0+1 more2007-08-18
CVE-2007-4423 [MEDIUM] CWE-119 CVE-2007-4423: Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fi
Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attackers to cause a denial of service and possibly execute arbitrary code via a long argument.
nvd
CVE-2004-1372P4HIGHCVSS 7.2v7.0v7.1+2 more2004-09-01
CVE-2004-1372 [HIGH] CVE-2004-1372: Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary
Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.
nvd
CVE-2005-4864P4HIGHCVSS 7.2v7.0v7.1+3 more2005-12-31
CVE-2005-4864 [HIGH] CWE-119 CVE-2005-4864: Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitr
Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable.
nvd
CVE-2007-1086P4HIGHCVSS 7.2v8.0v8.1+13 more2007-02-23
CVE-2007-1086 [HIGH] CVE-2007-1086: Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users
Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to "unsafe file access."
nvd
CVE-2009-0173P4MEDIUMCVSS 5.0v9.1v9.52009-01-16
CVE-2009-0173 [MEDIUM] CWE-20 CVE-2009-0173: Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before F
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.
nvd
CVE-2002-1583P4HIGHCVSS 7.2v6.0v7.0+3 more2004-09-28
CVE-2002-1583 [HIGH] CVE-2002-1583: Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local u
Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.
nvd