![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1439
https://notcve.org/view.php?id=CVE-2017-1439
12 Sep 2017 — IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058. IBM DB2 para Linux, UNIX y Windows 9.7, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local con privilegios de propietario en la instancia DB2 obtener acceso root. IBM X-Force ID: 128058. • http://www.ibm.com/support/docview.wss?uid=swg22006061 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1451
https://notcve.org/view.php?id=CVE-2017-1451
12 Sep 2017 — IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178. IBM DB2 para Linux, UNIX y Windows 9.7, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local con privilegios de propietario en la instancia DB2 obtener acceso root. IBM X-Force ID: 128178. • http://www.ibm.com/support/docview.wss?uid=swg22006061 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1438
https://notcve.org/view.php?id=CVE-2017-1438
12 Sep 2017 — IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057. IBM DB2 para Linux, UNIX y Windows 9.7, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local con privilegios de propietario en la instancia DB2 obtener acceso root. IBM X-Force ID: 128057. • http://www.ibm.com/support/docview.wss?uid=swg22006885 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1520
https://notcve.org/view.php?id=CVE-2017-1520
12 Sep 2017 — IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830. IBM DB2 9.7, 10,1, 10.5 y 11.1 es vulnerable a que se ejecute un comando no autorizado que permita activar la base de datos cuando la autenticación es de tipo CLIENT. IBM X-Force ID: 129830. • http://www.ibm.com/support/docview.wss?uid=swg22007186 • CWE-287: Improper Authentication •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1452
https://notcve.org/view.php?id=CVE-2017-1452
12 Sep 2017 — IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180. IBM DB2 para Linux, UNIX y Windows 9.7, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) podría permitir a un usuario local obtener privilegios elevados y sobrescribir archivos DB2.. IBM X-Force ID: 128180. • http://www.ibm.com/support/docview.wss?uid=swg22006109 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1105
https://notcve.org/view.php?id=CVE-2017-1105
27 Jun 2017 — IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668. IBM DB2 para Linux, UNIX y Windows 9.2, 10,1, 10.5 y 11.1 (incluido DB2 Connect Server) es vulnerable a un desbordamiento de búfer que podría permitir que un usuario local sobrescriba archivos DB2 o provoque una denegación de servicio (DoS). IBM X-Force ID: 120668. • http://www.ibm.com/support/docview.wss?uid=swg22003877 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1297 – IBM DB2 9.7/10.1/10.5/11.1 - Command Line Processor Buffer Overflow
https://notcve.org/view.php?id=CVE-2017-1297
26 Jun 2017 — IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159. IBM DB2 para Linux, Unix y Windows 9.2, 10.1, 10.5 y 11.1 (incluido DB2 Connect Server) es vulnerable a un buffer overflow basado en pila --stack-- causado por una inapropiada verificación de límites lo que podría permitir a un atacante local ejecutar... • https://packetstorm.news/files/id/143145 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-5995
https://notcve.org/view.php?id=CVE-2016-5995
01 Oct 2016 — Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program. Vulnerabilidad de ruta de búsqueda no confiable en IBM DB2 9.7 hasta la versión FP11, 10.1 hasta la versión FP5, 10.5 en versiones anteriores a FP8 y 11.1 GA en Linux, AIX y HP-UX permite a usuarios locales obtener privilegios a través de una librería troyanizad... • http://www-01.ibm.com/support/docview.wss?uid=swg1IT16921 • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2016-0211
https://notcve.org/view.php?id=CVE-2016-0211
28 Apr 2016 — IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message. IBM DB2 9.7 hasta la versión FP11, 9.8 y 10.1 hasta la versión FP5, y 10.5 hasta la versión FP7 en Linux, UNIX y Windows permite a usuarios remotos autenticados causar una denegación de servicio (caída de demonio) a través de un mensaje DRDA manipulado. • http://www-01.ibm.com/support/docview.wss?uid=swg1IT12462 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-6717
https://notcve.org/view.php?id=CVE-2013-6717
19 Dec 2013 — The OLAP query engine in IBM DB2 and DB2 Connect 9.7 through FP9, 9.8 through FP5, 10.1 through FP3, and 10.5 through FP2, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service (database outage and deactivation) via unspecified vectors. El motor de consultas OLAP en IBM DB2 y DB2 Connect 9.7 hasta FP9, 9.8 hasta FP3, y 10.6 hasta FP2, y la pureScale Feature 9.8 para Enterprise Server Edition, permite ausuarios autenticados remotamente... • http://secunia.com/advisories/56451 •