Remote Click Hijacking Vulnerability in IBM Datacap
CVE-2025-36027

5.4MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
28 June 2025

What is CVE-2025-36027?

A remote click hijacking vulnerability exists in IBM Datacap versions 9.1.7, 9.1.8, and 9.1.9, enabling a malicious actor to exploit the system by persuading users to visit a crafted website. Upon doing so, the attacker can manipulate the victim's click actions, paving the way for additional exploitations and potential threats against the user's system. The flaw emphasizes the importance of safeguarding web interactions and user awareness.

Affected Version(s)

Datacap 9.1.7, 9.1.8, 9.1.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36027 : Remote Click Hijacking Vulnerability in IBM Datacap