IBM Db2 Mirror for i是美国国际商业机器(IBM)公司的一个确保关键数据库系统的高可用性、数据一致性和灾难恢复能力的软件。 IBM Db2 Mirror for i 7.4版本和7.5版本和7.6版本存在授权问题漏洞,该漏洞源于未禁止使用后的会话ID,可能导致用户冒充。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Db2 Mirror for i | 7.4, 7.5, 7.6 |
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-33076 | 8.8 HIGH | IBM Engineering Systems Design Rhapsody code execution |
| CVE-2025-33077 | 8.8 HIGH | IBM Engineering Systems Design Rhapsody code execution |
| CVE-2025-36116 | 6.3 MEDIUM | IBM Db2 Mirror for i cross-site websocket hijacking |
| CVE-2024-40682 | 6.2 MEDIUM | IBM SmartCloud Analytics - Log Analysis denial of service |
| CVE-2025-33020 | 5.9 MEDIUM | IBM Engineering Systems Design Rhapsody information disclosure |
| CVE-2024-41751 | 5.5 MEDIUM | IBM SmartCloud Analytics - Log Analysis security bypass |
| CVE-2024-41750 | 5.5 MEDIUM | IBM SmartCloud Analytics - Log Analysis security bypass |
| CVE-2024-40686 | 5.4 MEDIUM | IBM SmartCloud Analytics - Log Analysis HOST header injection |
No comments yet