Home

Description

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation.  A user with access to the database plan cache could see information they do not have authority to view.

PUBLISHED Reserved 2025-04-15 | Published 2025-11-19 | Updated 2025-11-19 | Assigner ibm




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-598 Use of GET Request Method With Sensitive Query Strings

Product status

7.6
affected

7.5
affected

7.4
affected

7.3
affected

7.2
affected

References

www.ibm.com/support/pages/node/7251699 vendor-advisory patch

cve.org (CVE-2025-36371)

nvd.nist.gov (CVE-2025-36371)

Download JSON