CVE-2025-36117: IBM DB2 Mirror For I
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
Affected products
- IBM DB2 Mirror For I: version 7.4 only; version 7.5 only; version 7.6 only
Published 2025-07-23. Last modified 2026-06-17.