CVE-2025-27899

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.
References
Link Resource
https://www.ibm.com/support/pages/node/7259901 Vendor Advisory Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:windows:*:*

History

26 Feb 2026, 16:33

Type Values Removed Values Added
First Time Ibm db2 Recovery Expert
Ibm
CPE cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5.0:interim_fix_002:*:*:*:windows:*:*
References () https://www.ibm.com/support/pages/node/7259901 - () https://www.ibm.com/support/pages/node/7259901 - Vendor Advisory, Patch

18 Feb 2026, 17:51

Type Values Removed Values Added
Summary
  • (es) IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 revela información sensible en una variable de entorno que podría facilitar ataques posteriores contra el sistema.

17 Feb 2026, 20:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 20:22

Updated : 2026-02-26 16:33


NVD link : CVE-2025-27899

Mitre link : CVE-2025-27899

CVE.ORG link : CVE-2025-27899


JSON object : View

Products Affected

ibm

  • db2_recovery_expert
CWE
CWE-526

Cleartext Storage of Sensitive Information in an Environment Variable