CVE-2025-36033: IBM Engineering Lifecycle Management - Global Configuration Management is vulnerable to cross-site scripting
IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Management is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36033?
CVE-2025-36033 has a severity rating that indicates a medium risk due to its potential for cross-site scripting vulnerabilities.
How do I fix CVE-2025-36033?
To mitigate CVE-2025-36033, users should upgrade to the latest versions of IBM Engineering Lifecycle Management that address this vulnerability.
What versions are affected by CVE-2025-36033?
CVE-2025-36033 affects IBM Engineering Lifecycle Management - Global Configuration Management versions from 7.0.3 to 7.0.3 Interim Fix 017 and 7.1.0 to 7.1.0 Interim Fix 004.
Is CVE-2025-36033 an internal or external risk?
CVE-2025-36033 represents an external risk as it involves cross-site scripting which can be exploited by malicious users through the web application.
What are the potential impacts of CVE-2025-36033?
The impacts of CVE-2025-36033 may include unauthorized access to sensitive data and the ability for attackers to execute scripts in users' browsers.