5.4

CVE-2025-36033

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Management is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmEngineering Lifecycle Management Version7.0.3 Update-
IbmEngineering Lifecycle Management Version7.0.3 Updateifix002
IbmEngineering Lifecycle Management Version7.0.3 Updateifix003
IbmEngineering Lifecycle Management Version7.0.3 Updateifix004
IbmEngineering Lifecycle Management Version7.0.3 Updateifix005
IbmEngineering Lifecycle Management Version7.0.3 Updateifix006
IbmEngineering Lifecycle Management Version7.0.3 Updateifix007
IbmEngineering Lifecycle Management Version7.0.3 Updateifix008
IbmEngineering Lifecycle Management Version7.0.3 Updateifix009
IbmEngineering Lifecycle Management Version7.0.3 Updateifix010
IbmEngineering Lifecycle Management Version7.0.3 Updateifix011
IbmEngineering Lifecycle Management Version7.0.3 Updateifix012
IbmEngineering Lifecycle Management Version7.0.3 Updateifix013
IbmEngineering Lifecycle Management Version7.0.3 Updateifix014
IbmEngineering Lifecycle Management Version7.0.3 Updateifix015
IbmEngineering Lifecycle Management Version7.0.3 Updateifix016
IbmEngineering Lifecycle Management Version7.0.3 Updateifix017
IbmEngineering Lifecycle Management Version7.1.0 Update-
IbmEngineering Lifecycle Management Version7.1.0 Updateifix001
IbmEngineering Lifecycle Management Version7.1.0 Updateifix0010
IbmEngineering Lifecycle Management Version7.1.0 Updateifix002
IbmEngineering Lifecycle Management Version7.1.0 Updateifix003
IbmEngineering Lifecycle Management Version7.1.0 Updateifix004
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
psirt@us.ibm.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.