Junglewise Threat Intelligence

CVE-2025-13755: IBM Db2 sensitive information disclosure in db2diag logs

CVE-2025-13755 · Severity: medium · CVSS 5.5 · Published 2026-05-26

Executive brief

IBM Db2, a widely used enterprise database system, is vulnerable to a security flaw where sensitive information, such as user credentials, is inadvertently written to system log files. An individual with local access to the server could read these logs to obtain sensitive data, potentially leading to unauthorized database access or further compromise of the system. This issue affects various versions of Db2 running on Linux, UNIX, and Windows platforms.

Technical details

IBM Db2 is vulnerable to an information disclosure vulnerability (CWE-532) in the db2diag logging component. The vulnerability occurs when specific testcase buckets are executed, causing the system to write potentially sensitive information, including credentials, into log files. A local attacker with low privileges can read these logs to extract sensitive data. The issue affects versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 on Linux, UNIX, and Windows. IBM has released special builds to remediate the issue and suggests reducing the diagnostic level (diaglevel) as a temporary mitigation.

Affected products

  • IBM Db2 for Linux, UNIX and Windows 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
  • IBM DB2 Connect Server 11.5.0 - 11.5.9, 12.1.0 - 12.1.4

Timeline

  • 2026-05-21: disclosed: Initial publication of the security bulletin
  • 2026-05-25: patched: Updated workaround and fix information provided
  • 2026-05-26: advisory: NVD publication date

References

Related threats