CVE-2025-36116 Details
Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
A cross-site WebSocket hijacking vulnerability has been identified in the IBM Db2 Mirror for i GUI, specifically in versions 7.4, 7.5, and 7.6. This vulnerability allows an unauthenticated malicious actor to send a specially crafted request that sniffs an existing WebSocket connection. Exploitation of this vulnerability could enable the attacker to remotely perform actions on behalf of the user that they are not authorized to.
Users can apply a PTF to IBM i to address this vulnerability. The PTF numbers for each affected Db2 Mirror for i release are as follows: - Version 7.4: PTF SJ05739 - Version 7.5: PTF SJ05742 - Version 7.6: PTF SJ05744
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7240351 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1385 | Missing Origin Validation in WebSockets | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm db2 mirror for i | 7.4 7.5 7.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2025 | Initial Analysis | [email protected] |
| Jul 23, 2025 | New CVE Received | [email protected] |