CVE-2025-27899
Received
Received - Intake
Information Disclosure in IBM DB2 Recovery Expert via Environment Variable
Publication date: 2026-02-17
Last updated on: 2026-02-26
Assigner: IBM Corporation
Description
Description
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | db2_recovery_expert | 5.5.0 |
| ibm | db2_recovery_expert | 5.5.0 |
| ibm | db2_recovery_expert | 5.5.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-526 | The product uses an environment variable to store unencrypted sensitive information. |