CVE-2025-36418: Multiple vulnerabilities found in IBM ApplinX.
IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to craft or modify a JSON web token in order to impersonate another user or to elevate their privileges.
Other sources
IBM ApplinX is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens . An attacker may be able to craft or modify a JSON web token in order to impersonate another user or to elevate their privileges.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36418?
CVE-2025-36418 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-36418?
To fix CVE-2025-36418, upgrade to IBM ApplinX version 11.1.0.8 or apply the recommended patch.
What type of vulnerability is CVE-2025-36418?
CVE-2025-36418 is a privilege escalation vulnerability caused by improper verification of JWT tokens.
Who is affected by CVE-2025-36418?
CVE-2025-36418 affects users of IBM ApplinX versions up to and including 11.1.
What can an attacker do with CVE-2025-36418?
An attacker can potentially craft or modify a JSON web token to impersonate another user or elevate their privileges.