CVE-2025-36117 Details
Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
A session fixation vulnerability has been identified in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. This vulnerability allows an authenticated user to impersonate another user by not properly invalidating the session ID after use.
Users can apply a Program Temporary Fix (PTF) to address this vulnerability. The PTF numbers for the fixed versions are SJ05739 for 7.4, SJ05742 for 7.5, and SJ05744 for 7.6. These PTFs can be downloaded from the IBM Support Fix Central website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7240351 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-384 | Session Fixation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm db2 mirror for i | 7.4 7.5 7.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2025 | Initial Analysis | [email protected] |
| Jul 23, 2025 | New CVE Received | [email protected] |