Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Db2
(Ibm)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 264 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2018-05-25 | CVE-2018-1450 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140045. | Db2 | 5.5 | ||
2018-05-25 | CVE-2018-1449 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044. | Db2 | 5.5 | ||
2018-03-22 | CVE-2017-1677 | IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999. | Db2 | 7.8 | ||
2017-09-12 | CVE-2017-1520 | IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830. | Db2, Db2_connect | 3.7 | ||
2017-09-12 | CVE-2017-1519 | IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829. | Db2, Db2_connect | 5.9 | ||
2017-09-12 | CVE-2017-1434 | IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user. | Db2, Db2_connect | 4.7 | ||
2017-06-27 | CVE-2017-1297 | IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159. | Data_server_client, Data_server_driver_for_odbc_and_cli, Data_server_driver_package, Data_server_runtime_client, Db2, Db2_connect | 7.3 | ||
2017-06-27 | CVE-2017-1105 | IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668. | Data_server_client, Data_server_driver_for_odbc_and_cli, Data_server_driver_package, Data_server_runtime_client, Db2, Db2_connect | 7.1 | ||
2016-09-30 | CVE-2016-5995 | Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program. | Db2, Db2_connect | 7.3 | ||
2018-01-16 | CVE-2016-0215 | IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database. | Db2 | 6.5 |