5.9
CVE-2025-27903
- EPSS 0.02%
- Veröffentlicht 17.02.2026 19:32:05
- Zuletzt bearbeitet 26.02.2026 18:14:21
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data in a cleartext communication channel that could allow an attacker to obtain sensitive information using man in the middle techniques.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Recovery Expert Version5.5.0 Updateinterim_fix_002 SwPlatformlinux
Ibm ≫ Db2 Recovery Expert Version5.5.0 Updateinterim_fix_002 SwPlatformunix
Ibm ≫ Db2 Recovery Expert Version5.5.0 Updateinterim_fix_002 SwPlatformwindows
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.035 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.