CVE-2025-36119: IBM i authentication bypass
IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.
Other sources
IBM i is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36119?
CVE-2025-36119 has a moderate severity level due to the potential for authenticated users to gain elevated privileges.
How do I fix CVE-2025-36119?
To fix CVE-2025-36119, update your IBM i systems to the latest versions recommended by IBM.
Who is affected by CVE-2025-36119?
CVE-2025-36119 affects authenticated users of IBM i 7.3, 7.4, 7.5, and 7.6 with access to IBM Digital Certificate Manager for i.
What kind of attack does CVE-2025-36119 involve?
CVE-2025-36119 involves a web session hijacking attack that can allow an attacker to obtain elevated privileges.
Can CVE-2025-36119 be exploited remotely?
CVE-2025-36119 requires an authenticated user, so it generally cannot be exploited remotely without proper access.