CVE-2025-36116

July 23, 2025, 3:15 p.m.

6.3
Medium

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.

Product(s) Impacted

Vendor Product Versions
Ibm
  • Db2 Mirror For I
  • 7.4, 7.5, 7.6

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-1385
Missing Origin Validation in WebSockets
The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a ibm db2_mirror_for_i 7.4 / / / / / / /
a ibm db2_mirror_for_i 7.5 / / / / / / /
a ibm db2_mirror_for_i 7.6 / / / / / / /

CVSS Score

6.3 / 10

CVSS Data - 3.1

  • Attack Vector: NETWORK
  • Attack Complexity: LOW
  • Privileges Required: LOW
  • Scope: UNCHANGED
  • Confidentiality Impact: LOW
  • Integrity Impact: LOW
  • Availability Impact: LOW
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

    View Vector String

Timeline

Published: July 23, 2025, 3:15 p.m.
Last Modified: July 23, 2025, 3:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

psirt@us.ibm.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.