CVE-2025-36409: Multiple vulnerabilities found in IBM ApplinX.
IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM ApplinX is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36409?
CVE-2025-36409 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-36409?
To fix CVE-2025-36409, you should update to IBM ApplinX version 11.1.0.8 or later.
Who is affected by CVE-2025-36409?
CVE-2025-36409 affects all authenticated users of IBM ApplinX version 11.1.
What are the potential impacts of CVE-2025-36409?
The impacts of CVE-2025-36409 include potential credentials disclosure and unauthorized access within the Web UI.
Is there a workaround for CVE-2025-36409 if I cannot immediately update?
Currently, there are no documented workarounds for CVE-2025-36409, so updating is recommended.