Security Advisory

CVE-2025-36116

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-23 14:26:06
Last updated 2025-08-18 01:30:27
Assigner ibm
CVSS score 6.3
State PUBLISHED

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.