Skip to main content

Vendor/product archive

ibm / db2 CVEs

Beta · best-effort

341 CVEs tagged to ibm / db214 Critical, 96 High, 216 Medium, 15 Low, 0 Unrated.

CVE-2012-0713

Published Aug 24, 2012

Unspecified vulnerability in the XML feature in IBM DB2 9.7 before FP6 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary XML files via unknown vector…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2197

Published Jul 25, 2012

Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authe…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2196

Published Jul 25, 2012

IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote attackers to read arbitrary XML files via the (1) GET_WRAP_CFG_C or (2) GET_WRAP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2194

Published Jul 25, 2012

Directory traversal vulnerability in the SQLJ.DB2_INSTALL_JAR stored procedure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2180

Published Jun 20, 2012

The chaining functionality in the Distributed Relational Database Architecture (DRDA) module in IBM DB2 9.7 before FP6 and 9.8 before FP5 allows remote attackers to cause a denial…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1797

Published Mar 20, 2012

IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0712

Published Mar 20, 2012

The XML feature in IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 allows remote authenticated users to cause a denial of service (infinite loop) by calling the XMLPA…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0710

Published Mar 20, 2012

IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relationa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0709

Published Mar 20, 2012

IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1373

Published Nov 9, 2011

Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows lo…

CVSS 1.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-4061

Published Oct 18, 2011

Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1847

Published May 3, 2011

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1846

Published May 3, 2011

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0757

Published Feb 2, 2011

IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0731

Published Feb 1, 2011

Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3740

Published Oct 5, 2010

The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3738

Published Oct 5, 2010

The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHI…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3737

Published Oct 5, 2010

Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by ex…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3736

Published Oct 5, 2010

Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the connection concentrator is enabled, allows remote authenticated users to cause a den…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3735

Published Oct 5, 2010

The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted qu…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3734

Published Oct 5, 2010

The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain acc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3733

Published Oct 5, 2010

The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 341 CVEsPage 11 of 14