<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – IBM Db2</title>
  <link>https://cvedaily.com/pages/tags/ibm-db2.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ibm-db2.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – IBM Db2</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-6938 – IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploadi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6938</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6938</strong></p>
  <p>IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6053 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6053</guid>
    <pubDate>Wed, 27 May 2026 14:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6053</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6052 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to runnin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6052</guid>
    <pubDate>Wed, 27 May 2026 14:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6052</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6051 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6051</guid>
    <pubDate>Wed, 27 May 2026 14:17:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6051</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3676 – IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3676</guid>
    <pubDate>Wed, 27 May 2026 14:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3676</strong></p>
  <p>IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1718 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1718</guid>
    <pubDate>Wed, 27 May 2026 14:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1718</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13755 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13755</guid>
    <pubDate>Tue, 26 May 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13755</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1577 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1577</guid>
    <pubDate>Thu, 30 Apr 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1577</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36122 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36122</guid>
    <pubDate>Thu, 30 Apr 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36122</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14688 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14688</guid>
    <pubDate>Thu, 30 Apr 2026 22:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14688</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1352 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1352</guid>
    <pubDate>Thu, 23 Apr 2026 00:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1352</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3856 – IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3856</guid>
    <pubDate>Tue, 17 Mar 2026 23:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3856</strong></p>
  <p>IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-353</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33130 – IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33130</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33130</strong></p>
  <p>IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33124 – IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33124</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33124</strong></p>
  <p>IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27904 – IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27904</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27904</strong></p>
  <p>IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27903 – IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27903</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27903</strong></p>
  <p>IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an attacker to obtain sensitive information using man in the middle techniques.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27901 – IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27901</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27901</strong></p>
  <p>IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-644</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27900 – IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27900</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27900</strong></p>
  <p>IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain h…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27899 – IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive informat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27899</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27899</strong></p>
  <p>IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-526</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27898 – IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27898</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27898</strong></p>
  <p>IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an authenticated user to impersonate another user on the system.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13108 – IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13108</guid>
    <pubDate>Tue, 17 Feb 2026 20:22:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13108</strong></p>
  <p>IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-226</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36425 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36425</guid>
    <pubDate>Tue, 17 Feb 2026 18:20:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36425</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36247 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36247</guid>
    <pubDate>Tue, 17 Feb 2026 18:20:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36247</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14689 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14689</guid>
    <pubDate>Tue, 17 Feb 2026 18:20:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14689</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic with federated objects.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13867 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13867</guid>
    <pubDate>Tue, 17 Feb 2026 18:20:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13867</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39724 – IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39724</guid>
    <pubDate>Wed, 04 Feb 2026 21:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39724</strong></p>
  <p>IBM Db2 Big SQL on Cloud Pak for Data versions 7.6 (on CP4D 4.8), 7.7 (on CP4D 5.0), and 7.8 (on CP4D 5.1) do not properly limit the allocation of system resources. An authenticated user with internal knowledge of the environment could exploit this weakness to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36442 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36442</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36442</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36428 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36428</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36428</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36427 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36427</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36427</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36424 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36424</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36424</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to improper neutralization of special elements in data query logic.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36423 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36423</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36423</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36387 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36387</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36387</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 could allow an authenticated user to cause a denial of service when given specially crafted query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36384 – IBM Db2 for Windows 12.1.0 - 12.1.3  could allow a local user with filesystem ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36384</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36384</strong></p>
  <p>IBM Db2 for Windows 12.1.0 - 12.1.3  could allow a local user with filesystem access to escalate their privileges due to the use of an unquoted search path element.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36366 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36366</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36366</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service by executing a query that invokes the JSON_Object scalar function, which may trigger an unhandled exception leading to abnormal server termination.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36365 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36365</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36365</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remote storage aliases could allow an authenticated user to execute unauthorized commands due to an authorization bypass vulnerability using a user-controlled key.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36353 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36353</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36353</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36184 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36184</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36184</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36123 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36123</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36123</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service when copying large table containing XML data due to improper allocation of system resources.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36098 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36098</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36098</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36070 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36070</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36070</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3  is vulnerable to a denial of service as a trap may occur when selecting from certain types of tables.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36009 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36009</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36009</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to excessive use of a global variable.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36001 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36001</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36001</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2668 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2668</guid>
    <pubDate>Fri, 30 Jan 2026 22:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2668</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when an authenticated user creates a specially crafted query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14687 – IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14687</guid>
    <pubDate>Fri, 26 Dec 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14687</strong></p>
  <p>IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12740 – A Looker user with a Developer role could create a database connection using IBM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12740</guid>
    <pubDate>Mon, 24 Nov 2025 12:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12740</strong></p>
  <p>A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's parameters.  Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.   Self-hoste…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36186 – IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36186</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36186</strong></p>
  <p>IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations could allow a local user to execute malicious code that escalate their privileges to root due to execution of unnecessary privileges operated at a higher than minimum level.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36185 – IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36185</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36185</strong></p>
  <p>IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36136 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36136</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36136</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause a denial of service due to the database monitor script incorrectly detecting that the instance is still starting under specific conditions.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36131 – IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36131</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36131</strong></p>
  <p>IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party with physical access to the system.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36008 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Win...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36008</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36008</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper allocation of resources.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36006 – IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36006</guid>
    <pubDate>Fri, 07 Nov 2025 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36006</strong></p>
  <p>IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial due to the improper release of resources after use.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33012 – IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33012</guid>
    <pubDate>Fri, 07 Nov 2025 19:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33012</strong></p>
  <p>IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account lockout due to password use after expiration date.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-324</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2534 – IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2534</guid>
    <pubDate>Fri, 07 Nov 2025 19:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2534</strong></p>
  <p>IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47118 – IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47118</guid>
    <pubDate>Fri, 07 Nov 2025 19:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47118</strong></p>
  <p>IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33133 – IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33133</guid>
    <pubDate>Tue, 28 Oct 2025 00:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33133</strong></p>
  <p>IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due an out of bounds write.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33132 – IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33132</guid>
    <pubDate>Tue, 28 Oct 2025 00:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33132</strong></p>
  <p>IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of the size of the data that is being pointed to.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-467</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33131 – IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33131</guid>
    <pubDate>Tue, 28 Oct 2025 00:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33131</strong></p>
  <p>IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33126 – IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33126</guid>
    <pubDate>Tue, 28 Oct 2025 00:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33126</strong></p>
  <p>IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10768 – A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10768</guid>
    <pubDate>Sun, 21 Sep 2025 10:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10768</strong></p>
  <p>A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36071 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36071</guid>
    <pubDate>Tue, 29 Jul 2025 19:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36071</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query due to improper release of memory resources.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33114 – IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 



is vulnerable to denial of serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33114</guid>
    <pubDate>Tue, 29 Jul 2025 19:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33114</strong></p>
  <p>IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2     is vulnerable to denial of service with a specially crafted query under certain non-default conditions.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33092 – IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 

is vulnerable to a stack-based bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33092</guid>
    <pubDate>Tue, 29 Jul 2025 19:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33092</strong></p>
  <p>IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2   is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52894 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52894</guid>
    <pubDate>Tue, 29 Jul 2025 19:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52894</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51473 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51473</guid>
    <pubDate>Tue, 29 Jul 2025 19:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51473</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2   is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-49828 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49828</guid>
    <pubDate>Tue, 29 Jul 2025 19:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-49828</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36010 – IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 

could allow an unauthenticated us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36010</guid>
    <pubDate>Tue, 29 Jul 2025 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36010</strong></p>
  <p>IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2   could allow an unauthenticated user to cause a denial of service due to executable segments that are waiting for each other to release a necessary lock.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-833</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2533 – IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2533</guid>
    <pubDate>Tue, 29 Jul 2025 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2533</strong></p>
  <p>IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36117 – IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36117</guid>
    <pubDate>Wed, 23 Jul 2025 15:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36117</strong></p>
  <p>IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36116 – IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36116</guid>
    <pubDate>Wed, 23 Jul 2025 15:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36116</strong></p>
  <p>IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability.  By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-1385</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3050 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3050</guid>
    <pubDate>Thu, 29 May 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3050</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service when using Q replication due to the improper allocation of CPU resources.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-2518 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2518</guid>
    <pubDate>Thu, 29 May 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-2518</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1   is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-49350 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49350</guid>
    <pubDate>Thu, 29 May 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-49350</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1493 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1493</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1493</guid>
    <pubDate>Mon, 05 May 2025 21:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1493</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1       could allow an authenticated user to cause a denial of service due to concurrent execution of shared resources.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1493">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1000 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1000</guid>
    <pubDate>Mon, 05 May 2025 21:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1000</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1   could allow an authenticated user to cause a denial of service when connecting to a z/OS database due to improper handling of automatic client rerouting.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0915 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0915</guid>
    <pubDate>Mon, 05 May 2025 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0915</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1     under specific configurations could allow an authenticated user to cause a denial of service due to insufficient release of allocated memory resources.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1992 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1992</guid>
    <pubDate>Mon, 05 May 2025 17:18:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1992</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52903 – IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52903</guid>
    <pubDate>Thu, 01 May 2025 23:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52903</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40679 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40679</guid>
    <pubDate>Wed, 08 Jan 2025 01:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40679</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-30443 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30443</guid>
    <pubDate>Thu, 19 Dec 2024 02:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-30443</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41762 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41762</guid>
    <pubDate>Sat, 07 Dec 2024 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41762</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37071 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37071</guid>
    <pubDate>Sat, 07 Dec 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37071</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35160 – IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35160</guid>
    <pubDate>Sat, 23 Nov 2024 14:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35160</strong></p>
  <p>IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7.6 could allow an authenticated user to obtain sensitive information due to insufficient session expiration.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41761 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41761</guid>
    <pubDate>Sat, 23 Nov 2024 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41761</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45663 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45663</guid>
    <pubDate>Thu, 21 Nov 2024 11:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45663</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31880 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31880</guid>
    <pubDate>Wed, 23 Oct 2024 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31880</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37529 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37529</guid>
    <pubDate>Wed, 14 Aug 2024 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37529</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.  IBM X-Force ID:  294295.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35152 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35152</guid>
    <pubDate>Wed, 14 Aug 2024 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35152</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation. IBM X-Force ID:  292639.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35136 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35136</guid>
    <pubDate>Wed, 14 Aug 2024 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35136</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) federated server 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain non default conditions.  IBM X-Force ID:  291307.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31882 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31882</guid>
    <pubDate>Wed, 14 Aug 2024 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31882</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.  IBM X-Force ID:  287614.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-31870 – IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31870</guid>
    <pubDate>Sat, 15 Jun 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-31870</strong></p>
  <p>IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects.  This can be used by a malicious actor to gather information about users that can be targeted in further attacks.  IBM X-Force ID:  287174.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-31881 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31881</guid>
    <pubDate>Wed, 12 Jun 2024 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-31881</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user.  IBM X-Force ID:  287613.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-29267 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29267</guid>
    <pubDate>Wed, 12 Jun 2024 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-29267</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.  IBM X-Force ID:  287612.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-28762 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28762</guid>
    <pubDate>Wed, 12 Jun 2024 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-28762</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions.  IBM X-Force ID:  285246.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42005 – IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42005</guid>
    <pubDate>Wed, 29 May 2024 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42005</strong></p>
  <p>IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27254 – IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27254</guid>
    <pubDate>Wed, 03 Apr 2024 13:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27254</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions.  IBM X-Force ID:  283813.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25046 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25046</guid>
    <pubDate>Wed, 03 Apr 2024 13:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25046</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query.  IBM X-Force ID:  282953.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25030 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25030</guid>
    <pubDate>Wed, 03 Apr 2024 13:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25030</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user.  IBM X-Force ID:  281677.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22360 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22360</guid>
    <pubDate>Wed, 03 Apr 2024 13:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22360</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables.  IBM X-Force ID:  280905.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52296 – IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52296</guid>
    <pubDate>Wed, 03 Apr 2024 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52296</strong></p>
  <p>IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently.  IBM X-Force ID:  278547.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38729 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38729</guid>
    <pubDate>Wed, 03 Apr 2024 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38729</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38729">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
