Vulnerabilities > IBM > DB2 > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-10 CVE-2023-27867 Code Injection vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection.
network
low complexity
ibm CWE-94
8.8
2023-07-10 CVE-2023-27868 Code Injection vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes.
network
low complexity
ibm CWE-94
8.8
2023-07-10 CVE-2023-27869 Code Injection vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection.
network
low complexity
ibm CWE-94
8.8
2023-07-10 CVE-2023-30431 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking.
local
low complexity
ibm CWE-119
7.8
2023-07-10 CVE-2023-30442 Unspecified vulnerability in IBM DB2 11.1.4.7/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 federated server is vulnerable to a denial of service as the server may crash when using a specially crafted wrapper using certain options.
network
low complexity
ibm
7.5
2023-07-10 CVE-2023-30445 Unspecified vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables.
network
low complexity
ibm
7.5
2023-07-10 CVE-2023-30446 Unspecified vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables.
network
low complexity
ibm
7.5
2023-07-10 CVE-2023-30447 Unspecified vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables.
network
low complexity
ibm
7.5
2023-07-10 CVE-2023-30448 Unspecified vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables.
network
low complexity
ibm
7.5
2023-07-10 CVE-2023-30449 Unspecified vulnerability in IBM DB2 10.5.0.11/11.1.4.7/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.
network
low complexity
ibm
7.5