CVE-2025-27899

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7259901 Vendor Advisory Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:windows:*:*

History

No history.

Information

Published : 2026-02-17 20:22

Updated : 2026-02-26 16:33


NVD link : CVE-2025-27899

Mitre link : CVE-2025-27899

CVE.ORG link : CVE-2025-27899


JSON object : View

Products Affected

ibm

  • db2_recovery_expert
CWE
CWE-526

Cleartext Storage of Sensitive Information in an Environment Variable