IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.

Project Subscriptions

Vendors Products
Db2 Recovery Expert Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade to DB2 Recovery Expert for Linux, Unix and Windows v5.5.0.1 Interim Fix 8 available on Fix Central  here https://www.ibm.com/support/fixcentral/swg/selectFixes .


Workaround

No workaround given by the vendor.

History

Tue, 17 Mar 2026 22:30:00 +0000

Type Values Removed Values Added
Description IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.
Title IBM Db2 Recovery Expert Missing Integrity Check
First Time appeared Ibm
Ibm db2 Recovery Expert
Weaknesses CWE-353
CPEs cpe:2.3:a:ibm:db2_recovery_expert:5.5:if2:*:*:*:linux:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5:if2:*:*:*:unix:*:*
cpe:2.3:a:ibm:db2_recovery_expert:5.5:if2:*:*:*:windows:*:*
Vendors & Products Ibm
Ibm db2 Recovery Expert
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-17T22:22:43.825Z

Reserved: 2026-03-09T20:48:18.685Z

Link: CVE-2026-3856

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-17T23:16:17.647

Modified: 2026-03-17T23:16:17.647

Link: CVE-2026-3856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses