Vulnerabilities
Vulnerable Software
Ibm:  >> Db2  Security Vulnerabilities
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-09-10
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-10
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
CVSS Score
8.1
EPSS Score
0.002
Published
2026-09-10
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
CVSS Score
8.4
EPSS Score
0.002
Published
2026-08-12
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-12
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial of service due to a memory leak.
CVSS Score
3.3
EPSS Score
0.001
Published
2026-08-12
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
CVSS Score
5.5
EPSS Score
0.001
Published
2026-08-12
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-08-12
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
CVSS Score
8.4
EPSS Score
0.001
Published
2026-07-30
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
CVSS Score
6.2
EPSS Score
0.001
Published
2026-07-30


Contact Us

Shodan ® - All rights reserved