VendorsIBMdb2any version
Vulnerabilities

IBM DB2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

133CVEs
CVE-2007-2582
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the DB2JDS service on tcp/6789; and cause a denial of service via (2) an invalid LANG parameter or (2) a long packet that generates a "MemTree overflow."
Published 2007-05-09 · Modified
10.0EPSS 0.270
CVE-2007-3676
IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.
Published 2008-02-12 · Modified
10.0EPSS 0.043
CVE-2008-4692
The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.
Published 2008-10-22 · Modified
10.0EPSS 0.021
CVE-2026-10109
IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling
Published 2026-06-30 · Analyzed
9.8EPSS 0.009
CVE-2026-10543
IBM® Db2® is vulnerable to privilege escalation with a specially crafted query
Published 2026-08-12 · Analyzed
9.8EPSS 0.003
CVE-2026-10534
IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser
Published 2026-08-12 · Analyzed
9.8EPSS 0.002
CVE-2012-3324
Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.
Published 2012-09-25 · Modified
9.0EPSS 0.036
CVE-2025-33012
IBM Db2 improper account lockout
Published 2025-11-07 · Analyzed
8.8EPSS 0.002
CVE-2020-5025
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 193661.
Published 2021-03-11 · Modified
8.4EPSS 0.006
CVE-2023-47145
IBM Db2 for Windows privilege escalation
Published 2024-01-07 · Modified
8.4EPSS 0.002
CVE-2025-36384
IBM Db2 Privilege Escalation
Published 2026-01-30 · Analyzed
8.4EPSS 0.002
CVE-2026-10535
IBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell
Published 2026-07-30 · Analyzed
8.4EPSS 0.001
CVE-2025-36247
IBM Db2 XML External Entity Reference
Published 2026-02-17 · Analyzed
8.2EPSS 0.003
CVE-2026-87958
IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions
Published 2026-09-10 · Analyzed
8.1EPSS 0.002
CVE-2007-5652
IBM DB2 UDB 9.1 before Fixpak 4 does not properly manage storage of a list containing authentication information, which might allow attackers to cause a denial of service (instance crash) or trigger memory corruption. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.
Published 2007-10-23 · Modified
7.8EPSS 0.018
CVE-2020-4739
IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 188149.
Published 2020-11-20 · Modified
7.8EPSS 0.005
CVE-2026-9762
IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control
Published 2026-07-17 · Analyzed
7.8EPSS 0.002
CVE-2025-36186
IBM Db2 privilege escalation
Published 2025-11-07 · Analyzed
7.8EPSS 0.001
CVE-2011-0731
Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2011-02-01 · Modified
7.5EPSS 0.045
CVE-2020-5024
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the SSL handshake response. IBM X-Force ID: 193660.
Published 2021-03-11 · Modified
7.5EPSS 0.020
CVE-2007-5090
Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt data via unspecified vectors.
Published 2007-09-26 · Modified
7.5EPSS 0.019
CVE-2021-29702
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
Published 2021-06-16 · Modified
7.5EPSS 0.019
CVE-2008-3958
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959.
Published 2008-09-09 · Modified
7.5EPSS 0.016
CVE-2023-47701
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-46167
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-29258
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-38727
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-40687
IBM Db2 denial of service
Published 2023-12-04 · Modified
7.5EPSS 0.011
CVE-2023-29255
IBM DB2 for Linux, UNIX and Windows denial of service
Published 2023-04-27 · Modified
7.5EPSS 0.010
CVE-2023-26021
IBM Db2 denial of service
Published 2023-04-28 · Modified
7.5EPSS 0.010
CVE-2023-26022
IBM Db2 denial of service
Published 2023-04-28 · Modified
7.5EPSS 0.010
CVE-2023-27559
IBM Db2 denial of service
Published 2023-04-26 · Modified
7.5EPSS 0.009
CVE-2023-30991
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-40372
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-40373
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-45193
IBM Db2 denial of service
Published 2024-01-22 · Modified
7.5EPSS 0.008
CVE-2023-38720
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-40374
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-30987
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
CVE-2023-38740
IBM Db2 denial of service
Published 2023-10-16 · Modified
7.5EPSS 0.008
1 / 4Next →