6.3
CVE-2025-27898
- EPSS 0.15%
- Veröffentlicht 17.02.2026 20:22:01
- Zuletzt bearbeitet 26.02.2026 16:33:33
- Erkennungen
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an authenticated user to impersonate another user on the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Recovery Expert Version 5.5.0 Update interim_fix_002 SwPlatform linux
Ibm ≫ Db2 Recovery Expert Version 5.5.0 Update interim_fix_002 SwPlatform unix
Ibm ≫ Db2 Recovery Expert Version 5.5.0 Update interim_fix_002 SwPlatform windows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.048 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
https://www.ibm.com/support/pages/node/7259901