SB2026091421 - IBM Db2 Developer Extension update for spring boot
Published: September 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-40972)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to observable timing discrepancies in DevTools remote secret comparison when validating the remote secret over an adjacent network. A remote attacker can measure response timing to discover the secret and execute arbitrary code.
Exploitation is limited to attackers on the same network as the remote application, and successful secret recovery may allow uploading changed classes.
Remediation
Install update from vendor's website.