VendorsIBMdb2all versions
Vulnerabilities

IBM DB2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

353CVEs
CVE-2017-1438
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.
Published 2017-09-12 · Modified
7.2EPSS 0.004
CVE-2017-1439
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.
Published 2017-09-12 · Modified
7.2EPSS 0.004
CVE-2009-4330
Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.
Published 2009-12-16 · Modified
7.2EPSS 0.004
CVE-2012-1796
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
Published 2012-03-20 · Modified
7.2EPSS 0.003
CVE-2008-0697
Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.
Published 2008-02-12 · Modified
7.2EPSS 0.003
CVE-2010-3733
The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.
Published 2010-10-05 · Modified
7.2EPSS 0.003
CVE-2012-2197
Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.
Published 2012-07-25 · Modified
7.1EPSS 0.045
CVE-2017-1105
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.
Published 2017-06-27 · Modified
7.1EPSS 0.004
CVE-2026-16480
IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
Published 2026-08-12 · Analyzed
7.1EPSS 0.003
CVE-2011-4061
Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.
Published 2011-10-18 · Modified
6.9EPSS 0.004
CVE-2015-0157
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.
Published 2015-07-20 · Modified
6.8EPSS 0.025
CVE-2023-38729
IBM Db2 information disclosure
Published 2024-04-03 · Analyzed
6.8EPSS 0.006
CVE-2020-4230
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.
Published 2020-02-19 · Modified
6.7EPSS 0.004
CVE-2023-35012
IBM Db2 code execution
Published 2023-07-17 · Modified
6.7EPSS 0.002
CVE-2010-0462
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.
Published 2010-01-28 · Modified
6.51 PoCEPSS 0.075
CVE-2011-0757
IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.
Published 2011-02-02 · Modified
6.5EPSS 0.024
CVE-2011-1846
IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.
Published 2011-05-03 · Modified
6.5EPSS 0.023
CVE-2019-4386
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714.
Published 2019-07-01 · Modified
6.5EPSS 0.021
CVE-2009-3472
IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.
Published 2009-09-29 · Modified
6.5EPSS 0.020
CVE-2018-1977
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A remote, authenticated DB2 user could exploit this vulnerability by issuing a specially-crafted SELECT statement with TRUNCATE function. IBM X-Force ID: 154032.
Published 2018-12-14 · Modified
6.5EPSS 0.019
CVE-2018-1857
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see. IBM X-Force ID: 151155.
Published 2018-11-09 · Modified
6.5EPSS 0.017
CVE-2020-4200
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafted commands to cause a denial of service. IBM X-Force ID: 174914.
Published 2020-02-19 · Modified
6.5EPSS 0.016
CVE-2016-0215
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
Published 2018-01-16 · Modified
6.5EPSS 0.016
CVE-2009-4438
The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors.
Published 2009-12-28 · Modified
6.5EPSS 0.016
CVE-2022-22389
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740.
Published 2022-06-24 · Modified
6.5EPSS 0.015
CVE-2020-4161
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to incorrect handling of certain commands. IBM X-Force ID: 174341.
Published 2020-02-19 · Modified
6.5EPSS 0.014
CVE-2021-29777
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.
Published 2021-06-24 · Modified
6.5EPSS 0.014
CVE-2022-35637
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.
Published 2022-09-13 · Modified
6.5EPSS 0.013
CVE-2021-38931
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
Published 2021-12-09 · Modified
6.5EPSS 0.012
CVE-2021-20579
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.
Published 2021-06-24 · Modified
6.5EPSS 0.011
CVE-2022-22483
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
Published 2022-09-13 · Modified
6.5EPSS 0.011
CVE-2023-27859
IBM Db2 code execution
Published 2024-01-22 · Modified
6.5EPSS 0.010
CVE-2023-29256
IBM Db2 information disclosure
Published 2023-07-09 · Modified
6.5EPSS 0.008
CVE-2023-50308
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.008
CVE-2023-47141
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47158
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47746
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47747
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2024-22360
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
CVE-2024-25046
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
← Prev5 / 9Next →