CVE-2025-13755: IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 (special build interim fix via Fix Central)to a version that resolves this vulnerability.Fixed in 11.5.9 - Upgrade
Upgrade
IBM Db2 (special build interim fix via Fix Central)to a version that resolves this vulnerability.Fixed in 12.1.4
Event History
Frequently Asked Questions
What is the risk associated with CVE-2025-13755?
CVE-2025-13755 has a medium risk severity level of 5.5.
What are the potential impacts of CVE-2025-13755?
CVE-2025-13755 can lead to credential exposure, allowing sensitive information to be viewed by local users.
How can I mitigate the effects of CVE-2025-13755?
To fix CVE-2025-13755, download the special build containing the interim fix from Fix Central.
Which versions of IBM Db2 are affected by CVE-2025-13755?
CVE-2025-13755 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4.
Is there a way to check if my system is vulnerable to CVE-2025-13755?
You can verify if your system is vulnerable by checking the version of IBM Db2 you are currently running against the affected versions.