IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
| Software | From | Fixed in |
|---|---|---|
| ibm / db2_mirror_for_i | 7.5 | 7.5.x |
| ibm / db2_mirror_for_i | 7.4 | 7.4.x |
| ibm / db2_mirror_for_i | 7.6 | 7.6.x |