VendorsIBMdb2all versions
Vulnerabilities

IBM DB2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

353CVEs
CVE-2020-4420
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the execution of a terminate command. IBM X-Force ID: 180076.
Published 2020-07-01 · Modified
7.5EPSS 0.024
CVE-2009-3471
IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.
Published 2009-09-29 · Modified
7.5EPSS 0.024
CVE-2020-5024
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the SSL handshake response. IBM X-Force ID: 193660.
Published 2021-03-11 · Modified
7.5EPSS 0.020
CVE-2007-5090
Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors.
Published 2007-09-26 · Modified
7.5EPSS 0.019
CVE-2021-29702
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
Published 2021-06-16 · Modified
7.5EPSS 0.019
CVE-2010-3194
The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.
Published 2010-08-31 · Modified
7.5EPSS 0.018
CVE-2021-29703
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.
Published 2021-06-24 · Modified
7.5EPSS 0.017
CVE-2008-3958
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
Published 2008-09-09 · Modified
7.5EPSS 0.016
CVE-2021-29825
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.
Published 2021-09-16 · Modified
7.5EPSS 0.015
CVE-2021-20373
IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
Published 2021-12-09 · Modified
7.5EPSS 0.015
CVE-2023-30445
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30449
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30448
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30446
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2023-30447
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2009-4333
The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.
Published 2009-12-16 · Modified
7.5EPSS 0.013
CVE-2023-30442
IBM Db2 denial of service
Published 2023-07-10 · Modified
7.5EPSS 0.013
CVE-2008-0696
IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.
Published 2008-02-12 · Modified
7.5EPSS 0.012
CVE-2023-47701
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-45178
IBM Db2 denial of service
Published 2023-12-03 · Modified
7.5EPSS 0.011
CVE-2023-46167
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-40692
IBM Db2 denial of service
Published 2023-12-03 · Modified
7.5EPSS 0.011
CVE-2023-29258
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-38727
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-40687
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-29255
IBM DB2 for Linux, UNIX and Windows denial of service
Published 2023-04-27 · Modified
7.5EPSS 0.010
CVE-2023-26021
IBM Db2 denial of service
Published 2023-04-28 · Modified
7.5EPSS 0.010
CVE-2023-26022
IBM Db2 denial of service
Published 2023-04-28 · Modified
7.5EPSS 0.010
CVE-2022-22390
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.
Published 2022-06-24 · Modified
7.5EPSS 0.010
CVE-2023-27559
IBM Db2 denial of service
Published 2023-04-26 · Modified
7.5EPSS 0.009
CVE-2021-39002
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Published 2021-12-09 · Modified
7.5EPSS 0.009
CVE-2023-30991
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-40372
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-40373
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-45193
IBM Db2 denial of service
Published 2024-01-22 · Modified
7.5EPSS 0.008
CVE-2023-30987
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-38720
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-38728
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-38740
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-40374
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
← Prev3 / 9Next →