Db2 Universal Database

Vendor:

First CVE: Feb 16, 2001 · Active for 25 years

67
Total CVEs
More Total CVEs than 98% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Db2 Universal Database over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2001
25 years ago
Most Recent CVE
Oct 5, 2010
5,771 days ago

CVE Severity & Scoring

Db2 Universal Database67 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local1 (1.5%)
Network0 (0.0%)
Unknown66 (98.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (1.5%)
High0 (0.0%)
Unknown66 (98.5%)
User Interaction
None1 (1.5%)
Unknown66 (98.5%)
Required0 (0.0%)
Privileges Required
Low1 (1.5%)
High0 (0.0%)
None0 (0.0%)
Unknown66 (98.5%)

Top CVEs

Signals from CVEs in this product scope (67 CVEs).

67 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.
Feb 16, 20017.535NOYES
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named
Oct 20, 20047.229NOYES
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.
Dec 31, 200510.027NONO
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensi
Dec 31, 20057.127NOYES
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
Sep 28, 20047.227NOYES
Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.
Oct 6, 20037.227NOYES
Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.
Oct 6, 20037.227NOYES
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT
Jan 16, 20095.025NOYES
Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or caus
Aug 28, 20089.325NONO
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
Nov 20, 200710.025NONO

Exploit Exposure

Signals from CVEs in this product scope (67 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
11.9% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (67 CVEs).

Media Mentions

Signals from CVEs in this product scope (67 CVEs).

Top CNAs Publishing CVEs For Db2 Universal Database

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.575.94.0%01
9.1145.93.2%01
9.026.01.9%00
8.245.51.7%01
8.1.9a96.61.6%00
8.1.996.61.6%00
8.1.8a96.61.6%00
8.1.896.61.6%00
8.1.7b96.61.6%00
8.1.796.61.6%00
8.1.6c96.61.6%00
8.1.696.61.6%00
8.1.596.61.6%00
8.1.496.61.6%00
8.1226.11.3%00
8.1026.11.3%00
8.1227.52.3%03
8.0197.62.6%02
846.01.4%00
7.2167.92.4%04