CVE-2025-36116: CWE-1385 Missing Origin Validation in WebSockets in IBM Db2 Mirror for i
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
CVE-2025-36116: CWE-1385 Missing Origin Validation in WebSockets in IBM Db2 Mirror for i
Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- ibm
- Date Reserved
- 2025-04-15T21:16:17.124Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6880f613ad5a09ad00266d82
Added to database: 7/23/2025, 2:47:47 PM
Last updated: 7/23/2025, 2:47:47 PM
Views: 1
Related Threats
CVE-2025-36117: CWE-384 Session Fixation in IBM Db2 Mirror for i
MediumCVE-2025-29480: n/a
MediumCVE-2025-40596: CWE-121 Stack-based Buffer Overflow in SonicWall SMA 100 Series
UnknownCVE-2025-46099: n/a
HighCVE-2025-54090: CWE-253 Incorrect Check of Function Return Value in Apache Software Foundation Apache HTTP Server
MediumActions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.