CVE Vulnerabilities

CVE-2025-36371

Use of GET Request Method With Sensitive Query Strings

Published: Nov 19, 2025 | Modified: Nov 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache implementation.  A user with access to the database plan cache could see information they do not have authority to view.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

NameVendorStart VersionEnd Version
IIbm7.2 (including)7.2 (including)
IIbm7.3 (including)7.3 (including)
IIbm7.4 (including)7.4 (including)
IIbm7.5 (including)7.5 (including)
IIbm7.6 (including)7.6 (including)

Potential Mitigations

References