CVE-2025-36116

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
Configurations

No configuration.

History

23 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-23 15:15

Updated : 2025-07-25 15:29


NVD link : CVE-2025-36116

Mitre link : CVE-2025-36116

CVE.ORG link : CVE-2025-36116


JSON object : View

Products Affected

No product.

CWE
CWE-1385

Missing Origin Validation in WebSockets