
🚨*CVE* CVE-2025-27898 IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an authenticated user to impersonate another user on… https://www.cve.org/CVERecord?id=CVE-2025-27898 ----- Traducción: CVE-2025-27898 IBM… http://infoflow.cloud`
Post summary
The post announces that IBM DB2 Recovery Expert Interim Fix 002 fails to invalidate user sessions after a timeout, potentially allowing authenticated users to impersonate others, but no PoC, exploit code, or active exploitation evidence is provided.

