Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

DB2 — Vulnerabilities & Security Advisories 48

All 48 CVE vulnerabilities found in DB2, with AI-generated Chinese analysis, references, and POCs.

This page aggregates verified security vulnerabilities affecting IBM DB2, categorized by specific weakness types and relevant industry tags. It collects documented flaws across the database management system, covering historical advisories and recent updates from the past decade, excluding hypothetical or unconfirmed issues. Users can track the vendor's security bulletins, analyze the frequency of specific weakness classes, and review the complete vulnerability history of the DB2 product to identify recurring risk patterns and emerging threats.

Vendor: IBM

CVE ID Title CVSS Severity Published
CVE-2026-15955 IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths CWE-22 7.5 High 2026-09-14
CVE-2026-16702 IBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference CWE-476 6.5 Medium 2026-09-14
CVE-2026-17463 IBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption CWE-400 6.5 Medium 2026-09-14
CVE-2026-86087 IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system CWE-22 4.3 Medium 2026-09-10
CVE-2026-86093 IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions CWE-121 7.5 High 2026-09-10
CVE-2026-87958 IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions CWE-269 8.1 High 2026-09-10
CVE-2026-10534 IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser CWE-121 8.4 High 2026-08-12
CVE-2026-10543 IBM® Db2® is vulnerable to privilege escalation with a specially crafted query CWE-285 8.2 High 2026-08-12
CVE-2026-16480 IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data. CWE-602 4.3 Medium 2026-08-12
CVE-2026-18097 IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files. CWE-532 5.5 Medium 2026-08-12
CVE-2026-18096 IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak CWE-770 3.3 Low 2026-08-12
CVE-2026-10535 IBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell CWE-121 8.4 High 2026-07-30
CVE-2026-10695 IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries CWE-400 6.2 Medium 2026-07-30
CVE-2026-7771 IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service CWE-835 5.5 Medium 2026-07-17
CVE-2026-9762 IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control CWE-94 7.8 High 2026-07-17
CVE-2025-36372 IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables CWE-538 5.5 Medium 2026-06-30
CVE-2026-10109 IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling CWE-94 9.8 Critical 2026-06-30
CVE-2026-11906 IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user CWE-1284 6.5 Medium 2026-06-30
CVE-2026-6938 IBM® Db2® is vulnerable to authorization bypass when uploading to a remote object storage path with a special query CWE-285 6.5 Medium 2026-05-27
CVE-2026-6053 IBM® Db2® is vulnerable to a denial of service when a specially crafted query is run with range partitioned tables CWE-770 5.5 Medium 2026-05-27
CVE-2026-6052 IBM® Db2® is vulnerable to running out of memory when executing certain queries with MDC tables 6.5 Medium 2026-05-27
CVE-2026-6051 IBM® Db2® is vulnerable to a denial of service when executing a specially crafted query with a small statement heap CWE-400 5.5 Medium 2026-05-27
CVE-2026-1718 IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure CWE-770 7.1 High 2026-05-27
CVE-2025-13755 IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets CWE-532 5.5 Medium 2026-05-26
CVE-2026-1577 IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries 6.5 Medium 2026-04-30
CVE-2025-36122 IBM® Db2® is vulnerable to a denial of service with a specially crafted query when stmtheap is set to automatic CWE-770 6.5 Medium 2026-04-30
CVE-2025-14688 IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations CWE-1284 5.3 Medium 2026-04-30
CVE-2026-1352 IBM® Db2® is vulnerable to a trap or return SQLCODE -901 when compiling a specially crafted query with a defined index CWE-1284 6.5 Medium 2026-04-22
CVE-2025-36006 IBM Db2 denial of service CWE-404 6.5 Medium 2025-11-07
CVE-2025-36008 IBM Db2 denial of service CWE-770 6.5 Medium 2025-11-07

All 48 known CVE vulnerabilities affecting DB2 with full Chinese analysis, references, and POCs where available.