Db2

Vendor:

First CVE: Sep 28, 2004 · Active for 21 years

343
Total CVEs
More Total CVEs than 100% of tracked products
14.9
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Db2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 28, 2004
21 years ago
Most Recent CVE
Jul 17, 2026
8 days ago

CVE Severity & Scoring

Db2343 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local80 (23.3%)
Network149 (43.4%)
Unknown113 (32.9%)
Physical1 (0.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low211 (61.5%)
High19 (5.5%)
Unknown113 (32.9%)
User Interaction
None223 (65.0%)
Unknown113 (32.9%)
Required7 (2.0%)
Privileges Required
Low141 (41.1%)
High13 (3.8%)
None76 (22.2%)
Unknown113 (32.9%)

Top CVEs

Signals from CVEs in this product scope (343 CVEs).

343 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.
Jun 30, 20269.842NONO
Multiple buffer overflows in the DB2 JDBC Applet Server (DB2JDS) service in IBM DB2 9.x and earlier allow remote attackers to (1) execute arbitrary code via a crafted packet to the
May 10, 200710.039NONO
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
Jul 17, 20267.834NONO
Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2
Sep 28, 20047.233NOYES
Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM D
Oct 5, 201010.032NONO
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that
Jan 28, 20106.532NOYES
Stack-based buffer overflow in the SQL/PSM (aka SQL Persistent Stored Module) Stored Procedure (SP) infrastructure in IBM DB2 9.1, 9.5, 9.7 before FP7, 9.8, and 10.1 might allow re
Oct 20, 20128.530NONO
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user fro
Jun 30, 20266.529NONO
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modi
Dec 9, 20218.729NONO
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could re
Mar 22, 20189.129NONO

Exploit Exposure

Signals from CVEs in this product scope (343 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
1.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (343 CVEs).

Media Mentions

Signals from CVEs in this product scope (343 CVEs).

Top CNAs Publishing CVEs For Db2

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.8.0.574.92.7%00
9.8.0.484.92.6%00
9.8.0.384.92.6%00
9.8.0.214.32.1%00
9.8.0.114.32.1%00
9.8264.92.3%00
9.7.0.9186.31.3%00
9.7.0.8186.31.2%00
9.7.0.7186.31.2%00
9.7.0.6226.31.6%00
9.7.0.5246.11.6%00
9.7.0.4246.11.6%00
9.7.0.3256.01.5%00
9.7.0.2275.91.6%00
9.7.0.11136.30.9%00
9.7.0.10136.30.9%00
9.7.0.1285.91.6%00
9.7.0.0146.50.8%00
9.71086.21.6%02
9.5.0.945.23.0%00