First published: Wed Jan 22 2025(Updated: )
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Application Dependency Discovery Manager | >=7.3.0.0<=7.3.0.11 | |
<=7.3.0.0 - 7.3.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23227 has been classified as a medium severity vulnerability due to its potential impact on user data through stored cross-site scripting.
To fix CVE-2025-23227, update IBM Tivoli Application Dependency Discovery Manager to version 7.3.0.12 or later.
CVE-2025-23227 affects authenticated users of IBM Tivoli Application Dependency Discovery Manager versions 7.3.0.0 through 7.3.0.11.
CVE-2025-23227 is a stored cross-site scripting vulnerability that allows the injection of arbitrary JavaScript code.
The consequences of CVE-2025-23227 include potential alteration of the Web UI's functionality and risks to user data.