VYPR

Db2 Mirror for i

by IBM

CVEs (2)

  • CVE-2025-36117Jul 23, 2025
    risk 0.00cvss epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36116Jul 23, 2025
    risk 0.00cvss epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.