Vulnerabilities > IBM > DB2

DATE CVE VULNERABILITY TITLE RISK
2024-06-12 CVE-2024-31881 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user.
network
low complexity
ibm
6.5
2024-06-12 CVE-2024-28762 Allocation of Resources Without Limits or Throttling vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions.
network
low complexity
ibm CWE-770
6.5
2024-04-03 CVE-2023-38729 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.
network
low complexity
ibm
6.5
2024-04-03 CVE-2023-52296 Unspecified vulnerability in IBM DB2 11.5
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently.
network
high complexity
ibm
5.3
2024-04-03 CVE-2024-22360 Unspecified vulnerability in IBM DB2 11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables.
network
low complexity
ibm
6.5
2024-04-03 CVE-2024-25030 Unspecified vulnerability in IBM DB2 11.1
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm
5.5
2024-04-03 CVE-2024-25046 Unspecified vulnerability in IBM DB2 11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query.
network
low complexity
ibm
6.5
2024-04-03 CVE-2024-27254 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions.
network
low complexity
ibm
6.5
2024-01-22 CVE-2023-47141 Unspecified vulnerability in IBM DB2
IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query.
network
low complexity
ibm
6.5
2024-01-22 CVE-2023-27859 Unspecified vulnerability in IBM DB2
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases.
network
low complexity
ibm
6.5