Skip to main content

CVE-2025-36117: CWE-384 Session Fixation in IBM Db2 Mirror for i

Medium
VulnerabilityCVE-2025-36117cvecve-2025-36117cwe-384
Published: Wed Jul 23 2025 (07/23/2025, 14:27:08 UTC)
Source: CVE Database V5
Vendor/Project: IBM
Product: Db2 Mirror for i

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

Technical Details

Data Version
5.1
Assigner Short Name
ibm
Date Reserved
2025-04-15T21:16:17.124Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6880f613ad5a09ad00266d85

Added to database: 7/23/2025, 2:47:47 PM

Last updated: 7/23/2025, 2:47:47 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats