CVE-2024-40679
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-40679 is a newly disclosed vulnerability affecting IBM Db2 for Linux, UNIX, and Windows versions 11.5. This issue permits information disclosure, as data considered sensitive may be found within a log file under particular circumstances. IBM urges users to update their systems to mitigate this risk, as an attacker could potentially exploit this vulnerability to gain unauthorized insight into the affected database environment. The precise conditions leading to the log file exposure are yet to be fully understood, but IBM strongly advises administrators to closely monitor their systems for any unusual activity and apply the available patch as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM DB2
Affected Vendors
- IBM Corporation