Known vulnerabilities in IBM DB2 - page 6
Vendor:
IBM Corporation
Software:
IBM DB2
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_db2:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
239
Public exploits:
10
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
12.1.4
11.5.6
11.5.5
12.1.3
12.1.2
12.1.0
5.2.0
5.1
4.7
4.5
4.0
3.5
11.1.4 FP7
12.1.1
5.0.3
5.0
11.1
4.8
11.5.9
4.6
11.5.7000.1973
11.5.8
10.5 FP11
9.7 FP11
1
11.1.4.3
11.1.4.2
11.1.4.1
11.5.7
11.1.4.7
8.0.7.5
7.0.11.0
11.5.7.0
11.5.6.0
11.5.5.1
11.5.5.0
11.5.4.0
11.5.0.0
11.1.4.6
11.1.4.5
11.1.4.4 iFix001
11.1.3.3
11.1.2.2 iFix002
11.1.2.2 iFix001
11.1.2.2
11.1.1.1 iFix001
11.1.1.1
10.5.0.11
10.1.0.3a
9.7.0.3a
9.5.0.6a
9.5.0.4a
9.5.0.3b
9.5.0.3a
9.5.0.2a
9.0.1.7a
9.0.1.6a
9.0.1.4a
9.0.1.3a
9.0.1.2a
9.7.0.9a
9.1.0.12
11.1 FP5
11.5
11.1.4.4
11.1.3.3 iFix002
10.5.0.10
11.1.3.3 iFix001
10.1.0.6
11.1 FP3
10.5.0.9
11.1 FP2
11.1 FP1
10.5.0.8
11.1.0.0
9.7.0.10
10.1.0.5
9.7.0.11
9.8.0.2
9.8.0.1
10.5.0.7
10.5.0.6
10.5.0.5
10.5.0.4
9.5.0.10
10.5.0.3
10.1.0.4
9.7.0.7
9.7.0.8
9.7.0.9
10.5.0.2
10.5.0.1
10.1.0.3
10.1.0.2
10.1.0.1
10.5
10.1
9.8.0.5
9.5.0.6
9.7.0.6
9.5.0.5
9.1.0.1
9.1.0.8
9.1.0.11
9.1.0.6
9.1.0.7
9.1.0.4
9.1.0.5
9.1.0.2
9.1.0.3
9.5.0.2
9.5.0.3
9.5.0.1
9.1.0.10
9.1.0.9
9.5.0.8
9.5.0.9
9.5.0.7
9.5.0.4
9.8.0.4
9.8.0.3
9.7.0.5
9.8
9.7.0.3
9.7.0.4
9.7.0.2
9.7.0.1
9.7
9.5.0.0
8.2 fixpack15
9.1.0.0
8.2
8.1.7b
8.1.8
8.1.9a
8.10
8.12
8.1.6c
8.0
8.1
8.1.4
8.2.0
8.2.1
8.1.8a
8.1.9
8.1.7
8.1.5
8.1.6
8.2.2
9.0
10.5.0.0
10.1.0.0
9.8.0.0
9.7.0.0
Vulnerabilities (239)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU88069 - Exposure of sensitive information to an unauthorized actor CVE-2023-38729 |
CWE-200 | Low | 10.5 FP11, 11.1.4.7, 11.5.0.0, 11.5.8, 11.5.9 | 03.04.2024 |
SB2024040327 SB2024040521 SB2024040805 and 10 more |
||
| #VU88067 - Resource exhaustion CVE-2024-27254 |
CWE-400 | Low | 10.5 FP11, 11.1.4.7, 11.5.8, 11.5.9 | 03.04.2024 |
SB2024040325 SB2024040521 SB2024040805 and 10 more |
||
| #VU85469 - Improper input validation CVE-2024-20952 |
CWE-20 | Medium | - | 16.01.2024 |
SB2024011689 SB2024011690 SB2024011691 and 189 more |
||
| #VU85165 - Permissions, Privileges, and Access Controls CVE-2023-47145 |
CWE-264 | Low | 10.5 FP11, 11.1.4.7, 11.5.8, 11.5.9 | 09.01.2024 |
SB2024010916 SB2024012503 SB2024012510 and 9 more |
||
| #VU85128 - Resource exhaustion CVE-2023-45193 |
CWE-400 | Medium | 11.5.8, 11.5.9 | 09.01.2024 |
SB2024010913 SB2024012503 SB2024012510 and 11 more |
||
| #VU85127 - Improper Control of Generation of Code ('Code Injection') CVE-2023-27859 |
CWE-94 | Medium | 10.5 FP11, 11.1.4.7, 11.5, 11.5.9, 11.5.8 | 09.01.2024 |
SB2024010911 SB2024012503 SB2024012510 and 12 more |
||
| #VU84389 - Resource exhaustion CVE-2023-47701 |
CWE-400 | Medium | 10.5 FP11, 11.1.4.7, 11.5.0.0, 11.5.8, 11.5.9 | 13.12.2023 |
SB2023121334 SB2024032815 SB2024040818 and 10 more |
||
| #VU83267 - Improper input validation CVE-2023-5676 |
CWE-20 | Low | - | 20.11.2023 |
SB2023112010 SB2023112011 SB2023112726 and 101 more |
||
| #VU83242 - Resource exhaustion CVE-2023-43646 |
CWE-400 | Medium | 4.8 | 17.11.2023 |
SB2023111725 SB2024010322 SB2024013046 and 5 more |
||
| #VU83234 - Incorrect Comparison CVE-2023-45133 |
CWE-697 | Low | 4.8 | 17.11.2023 |
SB2023111710 SB2023111712 SB2023113028 and 25 more |
||
| #VU82141 - Improper input validation CVE-2023-22081 |
CWE-20 | Medium | - | 17.10.2023 |
SB2023101797 SB2023101798 SB2023101905 and 187 more |
||
| #VU78932 - Incorrect Regular Expression CVE-2022-25883 |
CWE-185 | Medium | 4.8 | 03.08.2023 |
SB2023080361 SB2023080362 SB2023081514 and 73 more |
||
| #VU70524 - Out-of-bounds write CVE-2022-41854 |
CWE-787 | Medium | 11.1.4.7 | 28.12.2022 |
SB2022122813 SB2022122926 SB2023010417 and 52 more |
||
| #VU70385 - Deserialization of Untrusted Data CVE-2022-1471 |
CWE-502 | High | 11.1.4.7 | 15.12.2022 |
SB2022121539 SB2022121540 SB2022121928 and 124 more |
||
| #VU67668 - Stack-based buffer overflow CVE-2022-38750 |
CWE-121 | Medium | 11.1.4.7 | 27.09.2022 |
SB2022092714 SB2022092728 SB2022100555 and 50 more |
||
| #VU67666 - Stack-based buffer overflow CVE-2022-38749 |
CWE-121 | Medium | 11.1.4.7 | 27.09.2022 |
SB2022092714 SB2022092728 SB2022100555 and 51 more |
||
| #VU67665 - Resource exhaustion CVE-2022-25857 |
CWE-400 | Medium | 11.1.4.7 | 27.09.2022 |
SB2022092714 SB2022092728 SB2022100555 and 83 more |
||
| #VU67664 - Stack-based buffer overflow CVE-2022-38752 |
CWE-121 | Medium | 11.1.4.7 | 27.09.2022 |
SB2022092715 SB2022092728 SB2022100555 and 66 more |
||
| #VU67663 - Out-of-bounds write CVE-2022-38751 |
CWE-787 | Medium | 11.1.4.7 | 27.09.2022 |
SB2022092714 SB2022092728 SB2022100555 and 50 more |
||
| #VU43781 - Improper input validation CVE-2012-2677 |
CWE-20 | Medium | 11.1.4.7, 11.5.8, 11.5.9 | 25.07.2012 |
SB2012072516 SB2021052604 SB2024040312 and 16 more |
Showing elements 101 - 120 out of 239