CVE Vulnerabilities

CVE-2024-40679

Insertion of Sensitive Information into Log File

Published: Jan 08, 2025 | Modified: Jan 31, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Db2Ibm11.5 (including)11.5 (including)

Potential Mitigations

References