CVE-2025-1551: IBM Operational Decision Manager cross-site scripting
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Operational Decision Manager is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1551?
CVE-2025-1551 has a high severity rating due to its potential impact on the security of IBM Operational Decision Manager.
How do I fix CVE-2025-1551?
To fix CVE-2025-1551, upgrade to a patched version of IBM Operational Decision Manager that mitigates the cross-site scripting vulnerability.
Who is affected by CVE-2025-1551?
CVE-2025-1551 affects users of IBM Operational Decision Manager versions 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1.
What type of vulnerability is CVE-2025-1551?
CVE-2025-1551 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2025-1551 be exploited remotely?
Yes, CVE-2025-1551 can be exploited by unauthenticated attackers remotely through the Web UI.