6.5

CVE-2025-36425

IBM Db2 Information Disclosure

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Db2 SwPlatform linux Version >= 11.5.0 <= 11.5.9
Ibm ≫ Db2 SwPlatform unix Version >= 11.5.0 <= 11.5.9
Ibm ≫ Db2 SwPlatform windows Version >= 11.5.0 <= 11.5.9
Ibm ≫ Db2 SwPlatform linux Version >= 12.1.0 <= 12.1.3
Ibm ≫ Db2 SwPlatform unix Version >= 12.1.0 <= 12.1.3
Ibm ≫ Db2 SwPlatform windows Version >= 12.1.0 <= 12.1.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.07
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
IBM 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-256 Plaintext Storage of a Password

The product stores a password in plaintext within resources such as memory or files.

https://www.ibm.com/support/pages/node/7259962
Vendor Advisory