Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 log plain‑text passwords to trace files. A local attacker with file system access can read these logs and obtain credentials used by the federated server, exposing sensitive authentication information. The vulnerability is a logging flaw (CWE‑532) and results in a local data‑exposure risk without enabling remote code execution or privilege escalation.
Affected Systems
The flaw affects IBM Db2 11.5 and 12.1 releases on Linux, UNIX, and Windows platforms, including the DB2 Connect Server component. Vulnerable versions are 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5. The description does not list specific minor releases beyond the numbered ranges, so all builds within those ranges are impacted.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation yet. Nonetheless, a local attacker with sufficient privileges to read the trace files can obtain login credentials. Exploitation requires only local access and no special network connectivity. The risk is primarily to confidentiality of authentication data; full system compromise is not achievable via this flaw alone.
OpenCVE Enrichment