CVE-2025-36027: IBM Datacap clickjacking
IBM Datacap 9.1.7, 9.1.8, and 9.1.9
could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Other sources
IBM Datacap could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36027?
CVE-2025-36027 is considered a high-severity vulnerability due to its potential for remote click hijacking.
How do I fix CVE-2025-36027?
To fix CVE-2025-36027, upgrade to IBM Datacap versions 9.1.10 or higher, ensuring all patches are applied.
Who is affected by CVE-2025-36027?
CVE-2025-36027 affects users of IBM Datacap versions 9.1.7, 9.1.8, and 9.1.9, as well as all versions of IBM Datacap Navigator.
What are the potential impacts of CVE-2025-36027?
Exploitation of CVE-2025-36027 can lead to unauthorized actions being performed on behalf of the victim by a remote attacker.
Is there a workaround for CVE-2025-36027?
Currently, it is recommended to upgrade to a non-affected version as there are no established workarounds for CVE-2025-36027.