CVE-2025-36026: IBM Datacap information disclosure
IBM Datacap 9.1.7, 9.1.8, and 9.1.9
does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36026?
CVE-2025-36026 is classified as a medium severity vulnerability due to the potential for cookie theft by attackers.
How do I fix CVE-2025-36026?
To mitigate CVE-2025-36026, configure your IBM Datacap application to set the secure attribute on authorization tokens and session cookies.
Which versions of IBM Datacap are affected by CVE-2025-36026?
CVE-2025-36026 affects IBM Datacap versions 9.1.7, 9.1.8, and 9.1.9, as well as all versions of IBM Datacap Navigator.
What is the exploit method for CVE-2025-36026?
Attackers can exploit CVE-2025-36026 by tricking users into clicking on malicious links that capture session cookies without the secure flag set.
What are the potential consequences of CVE-2025-36026?
If exploited, CVE-2025-36026 could allow attackers to hijack user sessions or access sensitive information through stolen cookies.