CVE-2026-3856 PUBLISHED

IBM Db2 Recovery Expert Missing Integrity Check

Assigner: ibm
Reserved: 09.03.2026 Published: 17.03.2026 Updated: 17.03.2026

IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor IBM
Product Db2 Recovery Expert
Versions Default: unaffected
  • Version 5.5 IF 2 is affected

Solutions

Upgrade to DB2 Recovery Expert for Linux, Unix and Windows v5.5.0.1 Interim Fix 8 available on Fix Central  here https://www.ibm.com/support/fixcentral/swg/selectFixes .

References

Problem Types

  • CWE-353 Missing support for integrity check CWE