IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 discloses sensitive information in an environment variable that could aid in further attacks against the system.
The product uses an environment variable to store unencrypted sensitive information.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Db2_recovery_expert | Ibm | 5.5.0-interim_fix_002 (including) | 5.5.0-interim_fix_002 (including) |