CVE-2026-18097: IBM® Db2® federated server could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
Other sources
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server)to a version that resolves this vulnerability.Fixed in 11.5.9Patch Security Update #88454 - Upgrade
Upgrade
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server)to a version that resolves this vulnerability.Fixed in 12.1.4Patch Security Update #88454 - Upgrade
Upgrade
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server)to a version that resolves this vulnerability.Fixed in 12.1.5Patch Security Update #88454
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18097?
CVE-2026-18097 has a medium severity rating of 5.5.
What type of vulnerability is CVE-2026-18097?
CVE-2026-18097 is a local information disclosure vulnerability that allows sensitive data exposure.
How can I mitigate CVE-2026-18097?
To mitigate CVE-2026-18097, ensure that logging does not include plain text passwords in trace files.
Which versions of IBM Db2 are affected by CVE-2026-18097?
CVE-2026-18097 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5.
Who can exploit CVE-2026-18097?
CVE-2026-18097 can be exploited by local attackers who have access to the trace files.