Ibm

Db2

355 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.07%
  • Veröffentlicht 22.10.2008 18:00:01
  • Zuletzt bearbeitet 16.06.2026 22:58:19

The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown imp...

  • EPSS 1.28%
  • Veröffentlicht 22.10.2008 18:00:01
  • Zuletzt bearbeitet 16.06.2026 22:58:19

The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."

  • EPSS 1.61%
  • Veröffentlicht 11.09.2008 01:13:47
  • Zuletzt bearbeitet 16.06.2026 22:56:53

IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue ...

  • EPSS 2.19%
  • Veröffentlicht 11.09.2008 01:13:47
  • Zuletzt bearbeitet 16.06.2026 22:56:53

IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/a...

  • EPSS 4.43%
  • Veröffentlicht 28.04.2008 20:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:54

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE...

  • EPSS 2.5%
  • Veröffentlicht 28.04.2008 20:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:54

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.

  • EPSS 2.68%
  • Veröffentlicht 27.04.2008 18:05:00
  • Zuletzt bearbeitet 16.06.2026 22:52:50

Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to ...

  • EPSS 4.33%
  • Veröffentlicht 13.02.2008 00:00:00
  • Zuletzt bearbeitet 16.06.2026 22:42:30

IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remo...

  • EPSS 1.16%
  • Veröffentlicht 12.02.2008 01:00:00
  • Zuletzt bearbeitet 16.06.2026 22:50:09

IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.

  • EPSS 0.3%
  • Veröffentlicht 12.02.2008 01:00:00
  • Zuletzt bearbeitet 16.06.2026 22:50:09

Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.