VendorsIBMdb211.1
Vulnerabilities

IBM DB2 11.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2017-1297
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
Published 2017-06-27 · Modified
7.31 PoCEPSS 0.015
CVE-2023-38003
IBM Db2 command execution
Published 2023-12-04 · Modified
7.2EPSS 0.011
CVE-2017-1105
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.
Published 2017-06-27 · Modified
7.1EPSS 0.004
CVE-2023-38729
IBM Db2 information disclosure
Published 2024-04-03 · Analyzed
6.8EPSS 0.006
CVE-2020-4230
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.
Published 2020-02-19 · Modified
6.7EPSS 0.004
CVE-2018-1977
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with TRUNCATE function. IBM X-Force ID: 154032.
Published 2018-12-14 · Modified
6.5EPSS 0.019
CVE-2018-1857
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see. IBM X-Force ID: 151155.
Published 2018-11-09 · Modified
6.5EPSS 0.017
CVE-2020-4200
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafted commands to cause a denial of service. IBM X-Force ID: 174914.
Published 2020-02-19 · Modified
6.5EPSS 0.016
CVE-2022-22389
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740.
Published 2022-06-24 · Modified
6.5EPSS 0.015
CVE-2021-29777
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.
Published 2021-06-24 · Modified
6.5EPSS 0.014
CVE-2022-35637
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.
Published 2022-09-13 · Modified
6.5EPSS 0.013
CVE-2021-38931
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
Published 2021-12-09 · Modified
6.5EPSS 0.012
CVE-2021-20579
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.
Published 2021-06-24 · Modified
6.5EPSS 0.011
CVE-2022-22483
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
Published 2022-09-13 · Modified
6.5EPSS 0.011
CVE-2024-27254
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
CVE-2024-25046
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
CVE-2024-31881
IBM Db2 denial of service
Published 2024-06-12 · Modified
6.5EPSS 0.006
CVE-2023-29267
IBM Db2 denial of service
Published 2024-06-12 · Modified
6.5EPSS 0.006
CVE-2024-28762
IBM Db2 denial of service
Published 2024-06-12 · Modified
6.5EPSS 0.006
CVE-2023-30443
IBM Db2 denial of service
Published 2024-12-19 · Analyzed
6.5EPSS 0.005
CVE-2018-1427
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a local attacker could overflow and cause a denial of service. IBM X-Force ID: 139072.
Published 2018-03-22 · Modified
6.2EPSS 0.004
CVE-2018-1799
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429.
Published 2018-11-09 · Modified
6.2EPSS 0.004
CVE-2020-4642
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".
Published 2020-12-23 · Modified
6.2EPSS 0.004
CVE-2018-1428
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.
Published 2018-03-22 · Modified
6.2EPSS 0.003
CVE-2024-25030
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.
Published 2024-04-03 · Analyzed
6.2EPSS 0.002
CVE-2018-1685
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
Published 2018-09-21 · Modified
5.5EPSS 0.004
CVE-2018-1449
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2018-1452
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2018-1450
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140045.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2018-1451
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140046.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2021-38926
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.
Published 2021-12-09 · Modified
5.5EPSS 0.003
CVE-2017-1571
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
Published 2018-03-22 · Modified
5.5EPSS 0.002
CVE-2024-41761
IBM Db2 denial of service
Published 2024-11-23 · Analyzed
5.3EPSS 0.004
CVE-2021-29763
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.
Published 2021-09-16 · Modified
5.1EPSS 0.003
CVE-2023-23487
IBM Db2 audit logging
Published 2023-07-09 · Modified
4.3EPSS 0.008
CVE-2017-1150
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.
Published 2017-03-08 · Modified
3.5EPSS 0.006
← Prev2 / 2