Cross-Site Request Forgery Vulnerability in IBM DB2 Recovery Expert for LUW
CVE-2025-27904

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
17 February 2026

What is CVE-2025-27904?

IBM DB2 Recovery Expert for LUW version 5.5 Interim Fix 002 is susceptible to cross-site request forgery (CSRF), potentially enabling unauthorized actions by exploiting the trust a website has in a user's browser. An attacker could craft a malicious request that, if executed by an unsuspecting user, might lead to unintended actions, compromising the application's integrity and security.

Affected Version(s)

DB2 Recovery Expert for LUW 5.5 Interim Fix 002

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.