Skip to main content

Exposure of Sensitive Information Through Environmental Variables

CVE-2025-27899

Severity Medium
Score 5.3/10

Summary

IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-526 - Exposure of Sensitive Information Through Environmental Variables

Environmental variables may contain sensitive information about a remote server.

References

Advisory Timeline

  • Published