CVE-2025-36116

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
References
Link Resource
https://www.ibm.com/support/pages/node/7240351 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*

History

07 Aug 2025, 14:36

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7240351 - () https://www.ibm.com/support/pages/node/7240351 - Vendor Advisory
Summary
  • (es) La interfaz gráfica de usuario de IBM Db2 Mirror para i 7.4, 7.5 y 7.6 se ve afectada por una vulnerabilidad de secuestro de WebSocket entre sitios. Al enviar una solicitud especialmente manipulada, un agente malicioso no autenticado podría explotar esta vulnerabilidad para rastrear una conexión WebSocket existente y, posteriormente, realizar de forma remota operaciones no permitidas para el usuario.
First Time Ibm
Ibm db2 Mirror For I
CPE cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*

23 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-23 15:15

Updated : 2025-08-07 14:36


NVD link : CVE-2025-36116

Mitre link : CVE-2025-36116

CVE.ORG link : CVE-2025-36116


JSON object : View

Products Affected

ibm

  • db2_mirror_for_i
CWE
CWE-1385

Missing Origin Validation in WebSockets