CVE-2026-15955
- EPSS 0.4%
- Veröffentlicht 14.09.2026 19:58:20
- Zuletzt bearbeitet 16.09.2026 19:24:58
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
CVE-2026-16702
- EPSS 0.35%
- Veröffentlicht 14.09.2026 19:43:19
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.
CVE-2026-17463
- EPSS 0.49%
- Veröffentlicht 14.09.2026 19:40:28
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.
CVE-2026-86087
- EPSS 0.22%
- Veröffentlicht 10.09.2026 21:24:33
- Zuletzt bearbeitet 14.09.2026 20:10:40
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
CVE-2026-86093
- EPSS 0.47%
- Veröffentlicht 10.09.2026 21:24:14
- Zuletzt bearbeitet 14.09.2026 20:10:27
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copie...
CVE-2026-87958
- EPSS 0.21%
- Veröffentlicht 10.09.2026 21:23:45
- Zuletzt bearbeitet 14.09.2026 20:10:14
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
CVE-2026-10534
- EPSS 0.38%
- Veröffentlicht 12.08.2026 21:24:30
- Zuletzt bearbeitet 17.08.2026 17:15:29
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
CVE-2026-10543
- EPSS 0.39%
- Veröffentlicht 12.08.2026 20:50:02
- Zuletzt bearbeitet 18.08.2026 15:08:19
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
CVE-2026-16480
- EPSS 0.34%
- Veröffentlicht 12.08.2026 20:49:02
- Zuletzt bearbeitet 18.08.2026 18:59:41
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
CVE-2026-18097
- EPSS 0.15%
- Veröffentlicht 12.08.2026 20:48:29
- Zuletzt bearbeitet 17.08.2026 18:39:35
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.