YottaDB is a distributed, open-source multi-model database system derived from GT.M that serves mission-critical applications in financial services and telecommunications, positioning it prominently within specialized infrastructure deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety and input-handling weakness classes including NULL-pointer dereferences, buffer overflows, improper input validation, and arithmetic errors that are characteristic of systems-level database engines. Defenders managing YottaDB instances should prioritize patching cycles and validate input handling at application boundaries; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yottadb over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44486CRITICAL An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c | Apr 15, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-27377CRITICAL An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_next_st and ydb_subscript_prev_st have a use-after-free. | Feb 18, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-44488CRITICAL An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnum | Apr 15, 2022 | 9.1 | 27 | NO | NO |
CVE-2021-44494HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointe | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44492HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the fu | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44491HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44490HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44489HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44487HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by deref | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44484HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to emit_trip in sr_port/emit_code.c allows attackers to crash the application by deref | Apr 15, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yottadb.
Media articles that mention a CVE ID that affects a product developed by Yottadb — matched by CVE ID, not by vendor name.