Vulnerabilities > IBM > DB2 > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-14 CVE-2024-37529 Unspecified vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.
network
low complexity
ibm
6.5
2024-06-12 CVE-2023-29267 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.
network
low complexity
ibm
6.5
2024-06-12 CVE-2024-31881 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user.
network
low complexity
ibm
6.5
2024-06-12 CVE-2024-28762 Allocation of Resources Without Limits or Throttling vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions.
network
low complexity
ibm CWE-770
6.5
2024-04-03 CVE-2023-38729 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.
network
low complexity
ibm
6.5
2024-04-03 CVE-2023-52296 Unspecified vulnerability in IBM DB2 11.5
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently.
network
high complexity
ibm
5.3
2024-04-03 CVE-2024-22360 Unspecified vulnerability in IBM DB2 11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables.
network
low complexity
ibm
6.5
2024-04-03 CVE-2024-25030 Unspecified vulnerability in IBM DB2 11.1
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm
5.5
2024-04-03 CVE-2024-25046 Unspecified vulnerability in IBM DB2 11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query.
network
low complexity
ibm
6.5
2024-04-03 CVE-2024-27254 Unspecified vulnerability in IBM DB2 10.5/11.1/11.5
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions.
network
low complexity
ibm
6.5