CVE-2025-36117: CWE-384 Session Fixation in IBM Db2 Mirror for i
Severity: mediumType: vulnerabilityCVE-2025-36117
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
CVE-2025-36117: CWE-384 Session Fixation in IBM Db2 Mirror for i
Medium
Published: Wed Jul 23 2025 (07/23/2025, 14:27:08 UTC)
Source: CVE Database V5
Vendor/Project: IBM
Product: Db2 Mirror for i
Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- ibm
- Date Reserved
- 2025-04-15T21:16:17.124Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6880f613ad5a09ad00266d85
Added to database: 7/23/2025, 2:47:47 PM
Last updated: 7/23/2025, 2:47:47 PM
Views: 1
Related Threats
CVE-2025-36116: CWE-1385 Missing Origin Validation in WebSockets in IBM Db2 Mirror for i
MediumVulnerabilityWed Jul 23 2025
CVE-2025-29480: n/a
MediumVulnerabilityWed Jul 23 2025
CVE-2025-40596: CWE-121 Stack-based Buffer Overflow in SonicWall SMA 100 Series
UnknownVulnerabilityWed Jul 23 2025
CVE-2025-46099: n/a
HighVulnerabilityWed Jul 23 2025
CVE-2025-54090: CWE-253 Incorrect Check of Function Return Value in Apache Software Foundation Apache HTTP Server
MediumVulnerabilityWed Jul 23 2025
Actions
Please log in to the Console to use AI analysis features.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.