<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM Db2 (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/ibm-db2.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-db2-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM Db2 (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-1718 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1718</guid>
    <pubDate>Wed, 27 May 2026 14:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1718</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36247 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36247</guid>
    <pubDate>Tue, 17 Feb 2026 18:20:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36247</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36384 – IBM Db2 for Windows 12.1.0 - 12.1.3  could allow a local user with filesystem ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36384</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36384</strong></p>
  <p>IBM Db2 for Windows 12.1.0 - 12.1.3  could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36184 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36184</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36184</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12740 – A Looker user with a Developer role could create a database connection using IBM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12740</guid>
    <pubDate>Mon, 24 Nov 2025 12:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12740</strong></p>
  <p>A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's parameters.  Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.   Self-hoste…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36186 – IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36186</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36186</strong></p>
  <p>IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33092 – IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 

is vulnerable to a stack-based bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33092</guid>
    <pubDate>Tue, 29 Jul 2025 19:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33092</strong></p>
  <p>IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2   is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42005 – IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42005</guid>
    <pubDate>Wed, 29 May 2024 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42005</strong></p>
  <p>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47145 – IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47145</guid>
    <pubDate>Sun, 07 Jan 2024 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47145</strong></p>
  <p>IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality.  IBM X-Force ID:  270402.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38003 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38003</guid>
    <pubDate>Mon, 04 Dec 2023 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38003</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a user with DATAACCESS privileges to execute routines that they should not have access to.  IBM X-Force ID:  260214.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30991 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30991</guid>
    <pubDate>Mon, 16 Oct 2023 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30991</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query.  IBM X-Force ID:  254037.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30449 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30449</guid>
    <pubDate>Mon, 10 Jul 2023 16:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30449</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.  IBM X-Force ID:  253439.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30445 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30445</guid>
    <pubDate>Mon, 10 Jul 2023 16:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30445</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables.  IBM X-Force ID:  253357.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30431 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30431</guid>
    <pubDate>Mon, 10 Jul 2023 16:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30431</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 db2set is vulnerable to a buffer overflow, caused by improper bounds checking.  An attacker could overflow the buffer and execute arbitrary code.  IBM X-Force ID:  252184.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27558 – IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27558</guid>
    <pubDate>Mon, 10 Jul 2023 16:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27558</strong></p>
  <p>IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted service path.   A local attacker could exploit this vulnerability to gain elevated privileges by inserting an executable file in the path of the affected service.  IBM X-Force ID:  249194.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26021 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26021</guid>
    <pubDate>Fri, 28 Apr 2023 19:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26021</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service as the server may crash when compiling a specially crafted SQL query using a LIMIT clause.  IBM X-Force ID:  247864.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29255 – IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29255</guid>
    <pubDate>Thu, 27 Apr 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29255</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block.  IBM X-Force ID:  251991.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29257 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29257</guid>
    <pubDate>Wed, 26 Apr 2023 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29257</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to remote code execution as a database administrator of one database may execute code or read/write files from another database within the same instance.  IBM X-Force ID:  252011.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22390 – IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22390</guid>
    <pubDate>Fri, 24 Jun 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22390</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39002 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39002</guid>
    <pubDate>Thu, 09 Dec 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39002</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29678 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29678</guid>
    <pubDate>Thu, 09 Dec 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29678</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-20373 – IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20373</guid>
    <pubDate>Thu, 09 Dec 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-20373</strong></p>
  <p>IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29825 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29825</guid>
    <pubDate>Thu, 16 Sep 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29825</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4945 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4945</guid>
    <pubDate>Thu, 24 Jun 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4945</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper group permissions. IBM X-Force ID: 191945.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4588 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4588</guid>
    <pubDate>Wed, 26 May 2021 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4588</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5025 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5025</guid>
    <pubDate>Thu, 11 Mar 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5025</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 193661.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5024 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5024</guid>
    <pubDate>Thu, 11 Mar 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5024</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the SSL handshake response. IBM X-Force ID: 193660.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4739 – IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4739</guid>
    <pubDate>Fri, 20 Nov 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4739</strong></p>
  <p>IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially crafted file in a compromised folder, an attacker could exploi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4701 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4701</guid>
    <pubDate>Thu, 19 Nov 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4701</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4420 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4420</guid>
    <pubDate>Wed, 01 Jul 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4420</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated attacker to cause a denial of service due a hang in the execution of a terminate command. IBM X-Force ID: 180076.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4363 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4363</guid>
    <pubDate>Wed, 01 Jul 2020 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4363</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 178960.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4204 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4204</guid>
    <pubDate>Wed, 19 Feb 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4204</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 174960.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4135 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4135</guid>
    <pubDate>Wed, 19 Feb 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4135</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthenticated user to send specially crafted packets to cause a denial of service from excessive memory usage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4606 – IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4606</guid>
    <pubDate>Thu, 12 Dec 2019 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4606</strong></p>
  <p>IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the system, caused by an untrusted search path vulnerability. By using a executable file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 168298.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4523 – IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4523</guid>
    <pubDate>Tue, 22 Oct 2019 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4523</strong></p>
  <p>IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 165481.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4448 – IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4448</guid>
    <pubDate>Mon, 26 Aug 2019 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4448</strong></p>
  <p>IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authority. IBM X-Force ID: 163489.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4447 – IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4447</guid>
    <pubDate>Mon, 26 Aug 2019 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4447</strong></p>
  <p>IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user controlled location. When a crash is induced the trojan gdb command is executed. IBM X-Force ID:…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4322 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4322</guid>
    <pubDate>Mon, 01 Jul 2019 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4322</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 161202.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4154 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4154</guid>
    <pubDate>Mon, 01 Jul 2019 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4154</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 158519.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4014 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4014</guid>
    <pubDate>Wed, 03 Apr 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4014</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1936 – IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1936</guid>
    <pubDate>Wed, 03 Apr 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1936</strong></p>
  <p>IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4094 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4094</guid>
    <pubDate>Thu, 21 Mar 2019 16:01:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4094</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4016 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4016</guid>
    <pubDate>Mon, 11 Mar 2019 22:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4016</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155894.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-4015 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4015</guid>
    <pubDate>Mon, 11 Mar 2019 22:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-4015</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 155893.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1980 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1980</guid>
    <pubDate>Mon, 11 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1980</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154078.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1978 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1978</guid>
    <pubDate>Mon, 11 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1978</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-ForceID: 154069.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1923 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1923</guid>
    <pubDate>Mon, 11 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1923</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152859.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1922 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1922</guid>
    <pubDate>Mon, 11 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1922</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 152858.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1897 – IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1897</guid>
    <pubDate>Fri, 30 Nov 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1897</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 152462.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1834 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1834</guid>
    <pubDate>Fri, 09 Nov 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1834</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to escalate their privileges to root through a symbolic link attack. IBM X-Force ID: 150511.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1802 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1802</guid>
    <pubDate>Fri, 09 Nov 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1802</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 149640.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1781 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1781</guid>
    <pubDate>Fri, 09 Nov 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1781</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148804.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1780 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1780</guid>
    <pubDate>Fri, 09 Nov 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1780</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148803.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1711 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1711</guid>
    <pubDate>Fri, 21 Sep 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1711</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1710 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1710</guid>
    <pubDate>Fri, 21 Sep 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1710</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1566 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1566</guid>
    <pubDate>Tue, 10 Jul 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1566</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1487 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1487</guid>
    <pubDate>Tue, 10 Jul 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1487</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1458 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1458</guid>
    <pubDate>Tue, 10 Jul 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1458</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10577 – ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10577</guid>
    <pubDate>Tue, 29 May 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10577</strong></p>
  <p>ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix. ibm_db before 1.0.2 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remo…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1565 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1565</guid>
    <pubDate>Fri, 25 May 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1565</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 143022.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1544 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1544</guid>
    <pubDate>Fri, 25 May 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1544</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 142648.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1515 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1515</guid>
    <pubDate>Fri, 25 May 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1515</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 141624.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1488 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1488</guid>
    <pubDate>Fri, 25 May 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1488</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1459 – IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1459</guid>
    <pubDate>Fri, 25 May 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1459</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based buffer overflow, caused by improper bounds checking which could lead an attacker to execute arbitrary code. IBM X-Force ID: 140210.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1448 – IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Conn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1448</guid>
    <pubDate>Thu, 22 Mar 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1448</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140043.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1426 – IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1426</guid>
    <pubDate>Thu, 22 Mar 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1426</strong></p>
  <p>IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-335</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1677 – IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1677</guid>
    <pubDate>Thu, 22 Mar 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1677</strong></p>
  <p>IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1452 – IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Conn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1452</guid>
    <pubDate>Tue, 12 Sep 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1452</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1451 – IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Conn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1451</guid>
    <pubDate>Tue, 12 Sep 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1451</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1297 – IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Conn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1297</guid>
    <pubDate>Tue, 27 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1297</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1105 – IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Conn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1105</guid>
    <pubDate>Tue, 27 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1105</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5995 – Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5995</guid>
    <pubDate>Sat, 01 Oct 2016 01:59:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5995</strong></p>
  <p>Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1935 – The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1935</guid>
    <pubDate>Mon, 20 Jul 2015 01:59:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1935</strong></p>
  <p>The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-17</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3094 – Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3094</guid>
    <pubDate>Thu, 04 Sep 2014 10:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3094</strong></p>
  <p>Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-0907 – Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0907</guid>
    <pubDate>Fri, 30 May 2014 23:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-0907</strong></p>
  <p>Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-6744 – The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6744</guid>
    <pubDate>Fri, 30 May 2014 23:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-6744</strong></p>
  <p>The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3475 – Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3475</guid>
    <pubDate>Wed, 05 Jun 2013 03:43:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3475</strong></p>
  <p>Stack-based buffer overflow in db2aud in the Audit Facility in IBM DB2 and DB2 Connect 9.1, 9.5, 9.7, 9.8, and 10.1, as used in Smart Analytics System 7600 and other products, allows local users to gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-4826 – Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) St...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4826</guid>
    <pubDate>Sat, 20 Oct 2012 10:41:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-4826</strong></p>
  <p>Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow remote authenticated users to execute arbitrary code by debugging a stored procedure.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-3324 – Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Conn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3324</guid>
    <pubDate>Tue, 25 Sep 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-3324</strong></p>
  <p>Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2197 – Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2197</guid>
    <pubDate>Wed, 25 Jul 2012 10:42:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2197</strong></p>
  <p>Stack-based buffer overflow in the Java Stored Procedure infrastructure in IBM DB2 9.1 before FP12, 9.5 through FP9, 9.7 through FP6, 9.8 through FP5, and 10.1 allows remote authenticated users to execute arbitrary code by leveraging certain CONNECT and EXECUTE privileges.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-1797 – IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1797</guid>
    <pubDate>Tue, 20 Mar 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-1797</strong></p>
  <p>IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1796 – Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1796</guid>
    <pubDate>Tue, 20 Mar 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1796</strong></p>
  <p>Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0711 – Integer signedness error in the db2dasrrm process in the DB2 Administration Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0711</guid>
    <pubDate>Tue, 20 Mar 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0711</strong></p>
  <p>Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through FP5 on UNIX platforms allows remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-0731 – Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0731</guid>
    <pubDate>Tue, 01 Feb 2011 18:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-0731</strong></p>
  <p>Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3733 – The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3733</guid>
    <pubDate>Tue, 05 Oct 2010 18:00:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3733</strong></p>
  <p>The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-3731 – Stack-based buffer overflow in the validateUser implementation in the com.ibm.db...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3731</guid>
    <pubDate>Tue, 05 Oct 2010 18:00:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-3731</strong></p>
  <p>Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3194 – The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3194</guid>
    <pubDate>Tue, 31 Aug 2010 22:00:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3194</strong></p>
  <p>The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-3193 – Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3193</guid>
    <pubDate>Tue, 31 Aug 2010 22:00:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-3193</strong></p>
  <p>Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1124 – bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1124</guid>
    <pubDate>Fri, 26 Mar 2010 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1124</strong></p>
  <p>bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-1041 – Unspecified vulnerability in the single sign-on functionality in the Web Service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1041</guid>
    <pubDate>Tue, 23 Mar 2010 00:53:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-1041</strong></p>
  <p>Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before FP13 on z/OS and DB2 Information Integrator for Content 8.3 before FP13 has unknown impact and remote attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-4335 – Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4335</guid>
    <pubDate>Wed, 16 Dec 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-4335</strong></p>
  <p>Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4333 – The Relational Data Services component in IBM DB2 9.5 before FP5 allows attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4333</guid>
    <pubDate>Wed, 16 Dec 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4333</strong></p>
  <p>The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4331 – The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4331</guid>
    <pubDate>Wed, 16 Dec 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4331</strong></p>
  <p>The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4330 – Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4330</guid>
    <pubDate>Wed, 16 Dec 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4330</strong></p>
  <p>Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-3473 – IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3473</guid>
    <pubDate>Tue, 29 Sep 2009 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-3473</strong></p>
  <p>IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-3471 – IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3471</guid>
    <pubDate>Tue, 29 Sep 2009 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-3471</strong></p>
  <p>IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-6821 – Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6821</guid>
    <pubDate>Wed, 03 Jun 2009 21:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-6821</strong></p>
  <p>Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-6820 – The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6820</guid>
    <pubDate>Wed, 03 Jun 2009 21:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-6820</strong></p>
  <p>The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-1231 – Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1231</guid>
    <pubDate>Thu, 02 Apr 2009 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-1231</strong></p>
  <p>Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-4692 – The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4692</guid>
    <pubDate>Wed, 22 Oct 2008 18:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-4692</strong></p>
  <p>The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4692">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
