CVE-2026-18097

Summary

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.

Affected Software

VendorProductVersion RangeStatus
IBMDb211.5.0 <= 11.5.9affected
IBMDb212.1.0 <= 12.1.5affected

Weaknesses

  • CWE-532: CWE-532 Insertion of Sensitive Information into Log File

References