Skip to main content

CVE-2025-36116: CWE-1385 Missing Origin Validation in WebSockets in IBM Db2 Mirror for i

Medium
VulnerabilityCVE-2025-36116cvecve-2025-36116cwe-1385
Published: Wed Jul 23 2025 (07/23/2025, 14:26:06 UTC)
Source: CVE Database V5
Vendor/Project: IBM
Product: Db2 Mirror for i

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.

Technical Details

Data Version
5.1
Assigner Short Name
ibm
Date Reserved
2025-04-15T21:16:17.124Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6880f613ad5a09ad00266d82

Added to database: 7/23/2025, 2:47:47 PM

Last updated: 7/23/2025, 2:47:47 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats