IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
History

Wed, 08 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jan 2025 01:15:00 +0000

Type Values Removed Values Added
Description IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
Title IBM Db2 information disclosure
First Time appeared Ibm
Ibm db2
Weaknesses CWE-532
CPEs cpe:2.3:a:ibm:db2:11.5:*:*:*:*:aix:*:*
cpe:2.3:a:ibm:db2:11.5:*:*:*:*:hp-ux:*:*
cpe:2.3:a:ibm:db2:11.5:*:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2:11.5:*:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2:11.5:*:*:*:*:windows:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-01-08T00:44:37.346Z

Updated: 2025-01-08T17:24:57.144Z

Reserved: 2024-07-08T19:30:52.528Z

Link: CVE-2024-40679

cve-icon Vulnrichment

Updated: 2025-01-08T17:24:53.612Z

cve-icon NVD

Status : Received

Published: 2025-01-08T01:15:06.953

Modified: 2025-01-08T01:15:06.953

Link: CVE-2024-40679

cve-icon Redhat

No data.