VendorsIBMdb211.5
Vulnerabilities

IBM DB2 11.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2023-27867
IBM Db2 code execution
Published 2023-07-08 · Modified
8.8EPSS 0.016
CVE-2023-27868
IBM Db2 code execution
Published 2023-07-08 · Modified
8.8EPSS 0.016
CVE-2023-27869
IBM Db2 code execution
Published 2023-07-08 · Modified
8.8EPSS 0.016
CVE-2021-29678
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.
Published 2021-12-09 · Modified
8.7EPSS 0.011
CVE-2020-4204
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 174960.
Published 2020-02-19 · Modified
8.4EPSS 0.006
CVE-2020-4701
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.
Published 2020-11-19 · Modified
8.4EPSS 0.005
CVE-2023-30431
IBM Db2 buffer overflow
Published 2023-07-09 · Modified
8.4EPSS 0.003
CVE-2023-27558
IBM Db2 privilege escalation
Published 2023-07-09 · Modified
8.4EPSS 0.002
CVE-2020-4945
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.
Published 2021-06-24 · Modified
8.1EPSS 0.010
CVE-2019-4588
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.
Published 2021-05-26 · Modified
7.8EPSS 0.003
CVE-2020-4135
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage.
Published 2020-02-19 · Modified
7.5EPSS 0.029
CVE-2021-29703
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.
Published 2021-06-24 · Modified
7.5EPSS 0.017
CVE-2021-29825
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.
Published 2021-09-16 · Modified
7.5EPSS 0.015
CVE-2021-20373
IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.
Published 2021-12-09 · Modified
7.5EPSS 0.015
CVE-2023-30445
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30449
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30448
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.014
CVE-2023-30447
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2023-30446
IBM Db2 denial of service
Published 2023-07-08 · Modified
7.5EPSS 0.013
CVE-2023-30442
IBM Db2 denial of service
Published 2023-07-10 · Modified
7.5EPSS 0.013
CVE-2023-45178
IBM Db2 denial of service
Published 2023-12-03 · Modified
7.5EPSS 0.011
CVE-2023-40692
IBM Db2 denial of service
Published 2023-12-03 · Modified
7.5EPSS 0.011
CVE-2022-22390
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.
Published 2022-06-24 · Modified
7.5EPSS 0.010
CVE-2021-39002
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Published 2021-12-09 · Modified
7.5EPSS 0.009
CVE-2022-43929
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2023-02-17 · Modified
7.5EPSS 0.007
CVE-2022-43927
IBM Db2 for Linux, UNIX and Windows information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.006
CVE-2022-43930
IBM Db2 for Linux, UNIX and Windows information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.005
CVE-2023-38003
IBM Db2 command execution
Published 2023-12-04 · Modified
7.2EPSS 0.011
CVE-2023-38729
IBM Db2 information disclosure
Published 2024-04-03 · Analyzed
6.8EPSS 0.006
CVE-2020-4230
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.
Published 2020-02-19 · Modified
6.7EPSS 0.004
CVE-2023-35012
IBM Db2 code execution
Published 2023-07-17 · Modified
6.7EPSS 0.002
CVE-2020-4200
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated attacker to send specially crafted commands to cause a denial of service. IBM X-Force ID: 174914.
Published 2020-02-19 · Modified
6.5EPSS 0.016
CVE-2022-22389
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740.
Published 2022-06-24 · Modified
6.5EPSS 0.015
CVE-2020-4161
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to incorrect handling of certain commands. IBM X-Force ID: 174341.
Published 2020-02-19 · Modified
6.5EPSS 0.014
CVE-2021-29777
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.
Published 2021-06-24 · Modified
6.5EPSS 0.014
CVE-2022-35637
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering a malformed SQL statement into the Db2expln tool. IBM X-Force ID: 230823.
Published 2022-09-13 · Modified
6.5EPSS 0.013
CVE-2021-38931
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
Published 2021-12-09 · Modified
6.5EPSS 0.012
CVE-2021-20579
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who can create a view or inline SQL function to obtain sensitive information when AUTO_REVAL is set to DEFFERED_FORCE. IBM X-Force ID: 199283.
Published 2021-06-24 · Modified
6.5EPSS 0.011
CVE-2022-22483
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979.
Published 2022-09-13 · Modified
6.5EPSS 0.011
CVE-2023-29256
IBM Db2 information disclosure
Published 2023-07-09 · Modified
6.5EPSS 0.008
1 / 2Next →