CVE-2025-36119

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.
References
Link Resource
https://www.ibm.com/support/pages/node/7241008 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

History

15 Aug 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 8.8
CPE cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
First Time Ibm i
Ibm
References () https://www.ibm.com/support/pages/node/7241008 - () https://www.ibm.com/support/pages/node/7241008 - Vendor Advisory

08 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-08 15:15

Updated : 2025-08-15 18:15


NVD link : CVE-2025-36119

Mitre link : CVE-2025-36119


JSON object : View

Products Affected

ibm

  • i
CWE
CWE-290

Authentication Bypass by Spoofing