Medium severity6.3NVD Advisory· Published Jul 23, 2025· Updated Jun 17, 2026
CVE-2025-36116
CVE-2025-36116
Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*range: 7.4, 7.5, 7.6
- (no CPE)range: 7.4, 7.5, and 7.6
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7240351nvdVendor Advisory
News mentions
0No linked articles in our index yet.