VendorsIBMdb2_recovery_expertall versions
Vulnerabilities

IBM DB2 Recovery Expert

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-3856
IBM Db2 Recovery Expert Missing Integrity Check
Published 2026-03-17 · Analyzed
9.1EPSS 0.002
CVE-2025-27900
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
Published 2026-02-17 · Analyzed
6.8EPSS 0.001
CVE-2025-27901
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
Published 2026-02-17 · Analyzed
6.5EPSS 0.002
CVE-2025-27904
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
Published 2026-02-17 · Analyzed
6.5EPSS 0.001
CVE-2025-27898
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
Published 2026-02-17 · Analyzed
6.3EPSS 0.002
CVE-2025-27903
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
Published 2026-02-17 · Analyzed
5.9EPSS 0.001
CVE-2025-27899
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
Published 2026-02-17 · Analyzed
5.3EPSS 0.002
CVE-2013-4024
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.
Published 2013-09-25 · Modified
4.3EPSS 0.011
CVE-2013-4022
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown vectors.
Published 2013-09-25 · Modified
3.5EPSS 0.009
CVE-2013-4025
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Published 2013-09-25 · Modified
1.9EPSS 0.005