Cross-Site Request Forgery Vulnerability in IBM DB2 Recovery Expert for LUW
CVE-2025-27904
6.5MEDIUM
What is CVE-2025-27904?
IBM DB2 Recovery Expert for LUW version 5.5 Interim Fix 002 is susceptible to cross-site request forgery (CSRF), potentially enabling unauthorized actions by exploiting the trust a website has in a user's browser. An attacker could craft a malicious request that, if executed by an unsuspecting user, might lead to unintended actions, compromising the application's integrity and security.
Affected Version(s)
DB2 Recovery Expert for LUW 5.5 Interim Fix 002