IBM / Db2
351 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-15955 | IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths | HIGH | 7.5 | Sep 14, 2026 |
| CVE-2026-16702 | IBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference | MEDIUM | 6.5 | Sep 14, 2026 |
| CVE-2026-17463 | IBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption | MEDIUM | 6.5 | Sep 14, 2026 |
| CVE-2026-86087 | IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system | MEDIUM | 4.3 | Sep 10, 2026 |
| CVE-2026-86093 | IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certai… | HIGH | 7.5 | Sep 10, 2026 |
| CVE-2026-87958 | IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions | HIGH | 8.1 | Sep 10, 2026 |
| CVE-2026-10534 | IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser | CRITICAL | 9.8 | Aug 12, 2026 |
| CVE-2026-10543 | IBM® Db2® is vulnerable to privilege escalation with a specially crafted query | CRITICAL | 9.8 | Aug 12, 2026 |
| CVE-2026-16480 | IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify d… | HIGH | 7.1 | Aug 12, 2026 |
| CVE-2026-18097 | IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. | MEDIUM | 5.5 | Aug 12, 2026 |
| CVE-2026-18096 | IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak | LOW | 3.3 | Aug 12, 2026 |
| CVE-2026-10535 | IBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell | HIGH | 8.4 | Jul 30, 2026 |
| CVE-2026-10695 | IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries | MEDIUM | 6.2 | Jul 30, 2026 |
| CVE-2026-7771 | IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service | MEDIUM | 5.5 | Jul 17, 2026 |
| CVE-2026-9762 | IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control | HIGH | 7.8 | Jul 17, 2026 |
| CVE-2025-36372 | IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables | MEDIUM | 6.5 | Jun 30, 2026 |
| CVE-2026-10109 | IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling | CRITICAL | 9.8 | Jun 30, 2026 |
| CVE-2026-11906 | IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived… | MEDIUM | 6.5 | Jun 30, 2026 |
| CVE-2023-33854 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. | MEDIUM | 5.3 | Jun 22, 2026 |
| CVE-2024-54178 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. | MEDIUM | 6.5 | Jun 22, 2026 |
| CVE-2025-2669 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data. | MEDIUM | 6.5 | Jun 22, 2026 |
| CVE-2026-6938 | IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query | HIGH | 7.5 | May 27, 2026 |
| CVE-2026-6053 | IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables | MEDIUM | 5.5 | May 27, 2026 |
| CVE-2026-6052 | IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables | HIGH | 7.5 | May 27, 2026 |
| CVE-2026-6051 | IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap | HIGH | 7.5 | May 27, 2026 |
Showing 1 to 25 of 351 CVEs