VendorsIBMdb2any version
Vulnerabilities

IBM DB2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

133CVEs
CVE-2009-2860
Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
Published 2009-08-19 · Modified
5.0EPSS 0.022
CVE-2009-2858
Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.
Published 2009-08-19 · Modified
5.0EPSS 0.017
CVE-2008-4693
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."
Published 2008-10-22 · Modified
5.0EPSS 0.013
CVE-2008-4691
Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors.
Published 2008-10-22 · Modified
5.0EPSS 0.012
CVE-2009-1239
IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.
Published 2009-04-03 · Modified
5.0EPSS 0.010
CVE-2011-1847
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information.
Published 2011-05-03 · Modified
4.9EPSS 0.020
CVE-2024-52894
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2025-07-29 · Analyzed
4.9EPSS 0.003
CVE-2009-2859
IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.
Published 2009-08-19 · Modified
4.6EPSS 0.004
CVE-2025-36131
IBM Db2 information disclosure
Published 2025-11-07 · Analyzed
4.6EPSS 0.002
CVE-2026-86087
IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system
Published 2026-09-10 · Analyzed
4.3EPSS 0.003
CVE-2010-1560
Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.
Published 2010-04-27 · Modified
4.0EPSS 0.016
CVE-2009-1905
The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.
Published 2009-06-03 · Modified
2.6EPSS 0.018
CVE-2011-1373
Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.
Published 2011-11-09 · Modified
1.5EPSS 0.003
← Prev4 / 4