VendorsIBMdb2all versions
Vulnerabilities

IBM DB2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

353CVEs
CVE-2018-1799
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivileged user to overwrite files on the system which could cause damage to the database. IBM X-Force ID: 149429.
Published 2018-11-09 · Modified
6.2EPSS 0.004
CVE-2019-4101
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of service. Users that have both EXECUTE on PD_GET_DIAG_HIST and access to the diagnostic directory on the DB2 server can cause the instance to crash. IBM X-Force ID: 158091.
Published 2019-07-01 · Modified
6.2EPSS 0.004
CVE-2020-4642
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".
Published 2020-12-23 · Modified
6.2EPSS 0.004
CVE-2020-4885
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow a local user to access and change the configuration of Db2 due to a race condition of a symbolic link,. IBM X-Force ID: 190909.
Published 2021-06-24 · Modified
6.2EPSS 0.003
CVE-2018-1428
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.
Published 2018-03-22 · Modified
6.2EPSS 0.003
CVE-2020-4386
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179268.
Published 2020-07-01 · Modified
6.2EPSS 0.002
CVE-2020-4387
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179269.
Published 2020-07-01 · Modified
6.2EPSS 0.002
CVE-2024-25030
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.
Published 2024-04-03 · Analyzed
6.2EPSS 0.002
CVE-2025-36353
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.2EPSS 0.002
CVE-2025-36123
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
6.2EPSS 0.001
CVE-2026-10695
IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries
Published 2026-07-30 · Analyzed
6.2EPSS 0.001
CVE-2025-36185
IBM Db2 denial of service
Published 2025-11-07 · Analyzed
6.2EPSS 0.001
CVE-2008-2154
IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.
Published 2009-06-03 · Modified
6.0EPSS 0.013
CVE-2017-1519
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829.
Published 2017-09-12 · Modified
5.9EPSS 0.017
CVE-2019-4102
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.
Published 2019-07-01 · Modified
5.9EPSS 0.012
CVE-2023-25930
IBM Db2 denial of service
Published 2023-04-28 · Modified
5.9EPSS 0.010
CVE-2018-1685
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
Published 2018-09-21 · Modified
5.5EPSS 0.004
CVE-2018-1449
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2018-1450
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140045.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2018-1451
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140046.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2018-1452
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.
Published 2018-05-25 · Modified
5.5EPSS 0.004
CVE-2021-38926
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.
Published 2021-12-09 · Modified
5.5EPSS 0.003
CVE-2017-1571
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
Published 2018-03-22 · Modified
5.5EPSS 0.002
CVE-2024-40679
IBM Db2 information disclosure
Published 2025-01-08 · Analyzed
5.5EPSS 0.002
CVE-2026-7771
IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service
Published 2026-07-17 · Analyzed
5.5EPSS 0.001
CVE-2026-18097
IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
Published 2026-08-12 · Analyzed
5.5EPSS 0.001
CVE-2026-6053
IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables
Published 2026-05-27 · Analyzed
5.5EPSS 0.001
CVE-2025-13755
IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets
Published 2026-05-26 · Analyzed
5.5EPSS 0.001
CVE-2025-36136
IBM denial of service
Published 2025-11-07 · Analyzed
5.5EPSS 0.001
CVE-2020-4355
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service, caused by improper handling of Secure Sockets Layer (SSL) renegotiation requests. By sending specially-crafted requests, a remote attacker could exploit this vulnerability to increase the resource usage on the system. IBM X-Force ID: 178507.
Published 2020-07-01 · Modified
5.3EPSS 0.022
CVE-2023-52296
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2024-04-03 · Analyzed
5.3EPSS 0.006
CVE-2024-41761
IBM Db2 denial of service
Published 2024-11-23 · Analyzed
5.3EPSS 0.004
CVE-2025-1493
IBM Db2 denial of service
Published 2025-05-05 · Modified
5.3EPSS 0.003
CVE-2025-36428
IBM Db2 Denial of Service
Published 2026-01-30 · Analyzed
5.3EPSS 0.003
CVE-2023-33854
Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.
Published 2026-06-22 · Analyzed
5.3EPSS 0.003
CVE-2025-14688
IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations
Published 2026-04-30 · Analyzed
5.3EPSS 0.002
CVE-2020-4976
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.
Published 2021-03-11 · Modified
5.1EPSS 0.003
CVE-2020-4414
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service. IBM X-Force ID: 179989.
Published 2020-07-01 · Modified
5.1EPSS 0.003
CVE-2021-29763
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Force ID: 202267.
Published 2021-09-16 · Modified
5.1EPSS 0.003
CVE-2023-38719
IBM Db2 denial of service
Published 2023-10-16 · Modified
5.1EPSS 0.002
← Prev7 / 9Next →