Ibm Db2 Universal Database vulnerabilities
66 known vulnerabilities affecting ibm/db2_universal_database.
Total CVEs
66
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH22MEDIUM32LOW3
Vulnerabilities
Page 4 of 4
CVE-2001-1143P4MEDIUMCVSS 5.0v7.02001-07-11
CVE-2001-1143 [MEDIUM] CVE-2001-1143: IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) d
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
nvd
CVE-2008-3857P4MEDIUMCVSS 4.6v9.12008-08-28
CVE-2008-3857 [MEDIUM] CWE-200 CVE-2008-3857: The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
nvd
CVE-2009-4150P4MEDIUMCVSS 4.6v82009-12-02
CVE-2009-4150 [MEDIUM] CWE-264 CVE-2009-4150: dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits executi
dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack vectors.
nvd
CVE-2003-1049P4MEDIUMCVSS 4.6v7.0v8.02004-09-28
CVE-2003-1049 [MEDIUM] CVE-2003-1049: IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissi
IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.
nvd
CVE-2007-4272P4LOWCVSS 1.9≤ 8.0≤ 9.12007-08-18
CVE-2007-4272 [LOW] CVE-2007-4272: Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users
Multiple vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to create arbitrary files via (1) unspecified vectors where an attacker's umask is honored, (2) /etc/ld.so.preload, (3) certain "cron data file locations", and other unspecified vectors possibly involving the (4) OSSEMEMDBG or (5) TRC_LOG_FILE environment variabl
nvd
CVE-2007-4271P4LOWCVSS 2.1≤ 8.0≤ 9.12007-08-18
CVE-2007-4271 [LOW] CWE-22 CVE-2007-4271: Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows l
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.
nvd
← Previous4 / 4