CVE-2025-36119

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.
References
Link Resource
https://www.ibm.com/support/pages/node/7241008 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

History

15 Aug 2025, 18:15

Type Values Removed Values Added
CPE cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
First Time Ibm
Ibm i
Summary
  • (es) IBM i 7.3, 7.4, 7.5 y 7.6 se ve afectado por un usuario autenticado que obtiene privilegios elevados con IBM Digital Certificate Manager para i (DCM) debido a una vulnerabilidad de secuestro de sesión web. Un usuario autenticado sin privilegios de administrador podría aprovechar esta vulnerabilidad para realizar acciones en DCM como administrador.
References () https://www.ibm.com/support/pages/node/7241008 - () https://www.ibm.com/support/pages/node/7241008 - Vendor Advisory

08 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-08 15:15

Updated : 2025-08-15 18:15


NVD link : CVE-2025-36119

Mitre link : CVE-2025-36119

CVE.ORG link : CVE-2025-36119


JSON object : View

Products Affected

ibm

  • i
CWE
CWE-290

Authentication Bypass by Spoofing