VYPR

Db2

by IBM

CVEs (373)

  • CVE-2020-4387MedJul 1, 2020
    risk 0.31cvss 4.7epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179269.

  • CVE-2020-4386MedJul 1, 2020
    risk 0.31cvss 4.7epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to obtain sensitive information using a race condition of a symbolic link. IBM X-Force ID: 179268.

  • CVE-2018-1857MedNov 9, 2018
    risk 0.31cvss 4.8epss 0.02

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gain access to data they shouldn't be able to see. IBM X-Force ID: 151155.

  • CVE-2017-1434MedSep 12, 2017
    risk 0.31cvss 4.7epss 0.00

    IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.

  • CVE-2025-36131MedNov 7, 2025
    risk 0.30cvss 4.6epss 0.00

    IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party with physical access to the system.

  • CVE-2021-29752MedSep 16, 2021
    risk 0.29cvss 4.4epss 0.01

    IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.

  • CVE-2020-4976MedMar 11, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.

  • CVE-2020-4414MedJul 1, 2020
    risk 0.29cvss 4.4epss 0.00

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local attacker to perform unauthorized actions on the system, caused by improper usage of shared memory. By sending a specially-crafted request, an attacker could…

  • CVE-2026-16480MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.

  • CVE-2023-23487MedJul 10, 2023
    risk 0.28cvss 4.3epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918.

  • CVE-2016-0211MedApr 28, 2016
    risk 0.28cvss 4.3epss 0.02

    IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.

  • CVE-2017-1520LowSep 12, 2017
    risk 0.24cvss 3.7epss 0.01

    IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.

  • CVE-2026-18096LowAug 12, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.

  • CVE-2024-31870LowJun 15, 2024
    risk 0.21cvss 3.3epss 0.00

    IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that…

  • CVE-2017-1150LowMar 8, 2017
    risk 0.20cvss 3.1epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.

  • CVE-2010-0462Jan 28, 2010
    risk 0.04cvss epss 0.08

    Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.

  • CVE-2009-0172Jan 16, 2009
    risk 0.04cvss epss 0.08

    Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.

  • CVE-2005-4869Dec 31, 2005
    risk 0.03cvss epss 0.01

    The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference.

  • CVE-2004-0795Oct 20, 2004
    risk 0.03cvss epss 0.02

    DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.

  • CVE-2003-1052Sep 28, 2004
    risk 0.03cvss epss 0.01

    IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.

Page 12 of 19