CVE-2025-27899

MEDIUM

IBM DB2 Recovery Expert 5.5 IF002 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.

References (1)

Core 1
Core References
Various Sources vendor-advisory patch
https://www.ibm.com/support/pages/node/7259901

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 11.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-526
Status published
Products (1)
ibm/db2_recovery_expert 5.5.0 interim_fix_002 (3 CPE variants)
Published Feb 17, 2026
Tracked Since Feb 18, 2026