6.5
CVE-2025-27904
- EPSS 0.11%
- Veröffentlicht 17.02.2026 19:30:28
- Zuletzt bearbeitet 26.02.2026 18:14:50
- Erkennungen
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 Recovery Expert Version 5.5.0 Update interim_fix_002 SwPlatform linux
Ibm ≫ Db2 Recovery Expert Version 5.5.0 Update interim_fix_002 SwPlatform unix
Ibm ≫ Db2 Recovery Expert Version 5.5.0 Update interim_fix_002 SwPlatform windows
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.017 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://www.ibm.com/support/pages/node/7259901