CVE-2025-36408: Multiple vulnerabilities found in IBM ApplinX.
IBM ApplinX 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM ApplinX is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36408?
CVE-2025-36408 has been classified as a high severity vulnerability due to its potential impact on user credentials and application integrity.
How do I fix CVE-2025-36408?
To fix CVE-2025-36408, upgrade to IBM ApplinX version 11.1.0.8 or apply the latest available patches as recommended by IBM.
Who is affected by CVE-2025-36408?
CVE-2025-36408 affects all authenticated users of IBM ApplinX version 11.1.
What kind of attack can CVE-2025-36408 enable?
CVE-2025-36408 can enable attackers to perform stored cross-site scripting (XSS) attacks allowing them to execute arbitrary JavaScript in the browser of the authenticated user.
What should I do if I cannot patch for CVE-2025-36408 immediately?
If immediate patching for CVE-2025-36408 is not possible, consider implementing input validation and output encoding to mitigate the risk of XSS attacks.