216.73.217.22

CVE-2025-36116

· Published 23/07/2025 15:15 · Modified 23/07/2025 15:15

Labels: CVE-2025-36116 2025-07-23CVE-2025-36116CWE-1385[email protected]

Essential information

Published
23/07/2025 15:15
Modified
23/07/2025 15:15
Author
Creator
CVSS
6.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / db2 mirror for i cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
ibm / db2 mirror for i cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
ibm / db2 mirror for i cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*

References