6.8
CVE-2025-27900
- EPSS 0.04%
- Veröffentlicht 17.02.2026 20:22:02
- Zuletzt bearbeitet 26.02.2026 18:04:54
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Recovery Expert Version5.5.0 Updateinterim_fix_002 SwPlatformlinux
Ibm ≫ Db2 Recovery Expert Version5.5.0 Updateinterim_fix_002 SwPlatformunix
Ibm ≫ Db2 Recovery Expert Version5.5.0 Updateinterim_fix_002 SwPlatformwindows
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.118 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| psirt@us.ibm.com | 6.8 | 2.3 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.