Session Management Flaw in IBM DB2 Recovery Expert for LUW
CVE-2025-27898
6.3MEDIUM
What is CVE-2025-27898?
The IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 features a session management flaw that fails to invalidate user sessions after a timeout. This vulnerability can be exploited by an authenticated user to impersonate another user, posing significant security risks to the affected systems. It is crucial for users of this product to implement available patches and review session management practices to mitigate potential threats.
Affected Version(s)
DB2 Recovery Expert for LUW 5.5 Interim Fix 002