VendorsIBMdb2any version
Vulnerabilities

IBM DB2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

133CVEs
CVE-2023-38720
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2024-45663
IBM Db2 denial of service
Published 2024-11-21 · Analyzed
7.5EPSS 0.007
CVE-2023-27555
IBM Db2 denial of service
Published 2023-04-28 · Modified
7.5EPSS 0.006
CVE-2023-47152
IBM Db2 information disclosure
Published 2024-01-22 · Modified
7.5EPSS 0.006
CVE-2026-86093
IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions
Published 2026-09-10 · Analyzed
7.5EPSS 0.004
CVE-2026-6052
IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables
Published 2026-05-27 · Analyzed
7.5EPSS 0.004
CVE-2025-36442
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
7.5EPSS 0.004
CVE-2024-49350
IBM Db2 denial of service
Published 2025-05-29 · Analyzed
7.5EPSS 0.004
CVE-2025-36070
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
7.5EPSS 0.004
CVE-2026-1718
IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure
Published 2026-05-27 · Analyzed
7.5EPSS 0.004
CVE-2024-52903
IBM Db2 denial of service
Published 2025-05-01 · Modified
7.5EPSS 0.003
CVE-2025-2518
IBM Db2 denial of service
Published 2025-05-29 · Analyzed
7.5EPSS 0.003
CVE-2026-6938
IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query
Published 2026-05-27 · Analyzed
7.5EPSS 0.003
CVE-2024-51473
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2026-6051
IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap
Published 2026-05-27 · Analyzed
7.5EPSS 0.003
CVE-2024-49828
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2025-36071
IBM Db2 denial of service
Published 2025-07-29 · Analyzed
7.5EPSS 0.003
CVE-2024-47118
IBM Db2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query
Published 2025-11-07 · Analyzed
7.5EPSS 0.003
CVE-2025-36365
IBM Db2 Privilege Escalation
Published 2026-01-30 · Analyzed
7.5EPSS 0.003
CVE-2025-2534
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
7.5EPSS 0.003
CVE-2023-29257
IBM Db2 code execution
Published 2023-04-26 · Modified
7.2EPSS 0.015
CVE-2025-36184
IBM Db2 Privilege Escalation
Published 2026-01-30 · Analyzed
7.2EPSS 0.005
CVE-2026-16480
IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
Published 2026-08-12 · Analyzed
7.1EPSS 0.003
CVE-2011-0757
IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.
Published 2011-02-02 · Modified
6.5EPSS 0.024
CVE-2011-1846
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
Published 2011-05-03 · Modified
6.5EPSS 0.023
CVE-2019-4386
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714.
Published 2019-07-01 · Modified
6.5EPSS 0.021
CVE-2023-27859
IBM Db2 code execution
Published 2024-01-22 · Modified
6.5EPSS 0.010
CVE-2023-50308
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.008
CVE-2023-47141
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47158
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47746
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47747
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2024-31882
IBM Db2 denial of service
Published 2024-08-14 · Modified
6.5EPSS 0.006
CVE-2024-35136
IBM Db2 denial of service
Published 2024-08-14 · Modified
6.5EPSS 0.006
CVE-2024-37529
IBM Db2 denial of service
Published 2024-08-14 · Modified
6.5EPSS 0.006
CVE-2024-54178
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
6.5EPSS 0.004
CVE-2026-11906
IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user
Published 2026-06-30 · Analyzed
6.5EPSS 0.004
CVE-2024-31880
IBM Db2 denial of service
Published 2024-10-23 · Modified
6.5EPSS 0.004
CVE-2024-41762
IBM Db2 denial of service
Published 2024-12-07 · Analyzed
6.5EPSS 0.004
CVE-2025-0915
IBM Db2 denial of service
Published 2025-05-05 · Modified
6.5EPSS 0.004
← Prev2 / 4Next →