CVE-2025-23227
published 2025-01-23CVE-2025-23227: IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.22%
12.2th percentile
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.3.0.0 – 7.3.0.11 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j53j-hp5h-xgg8: IBM Tivoli Application Dependency Discovery Manager 7
ghsa_unreviewed·2025-01-23
CVE-2025-23227 [MEDIUM] CWE-79 GHSA-j53j-hp5h-xgg8: IBM Tivoli Application Dependency Discovery Manager 7
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CISA
NUUO NVRmini2 Devices Missing Authentication Vulnerability
cisa·2024-12-18·CVSS 9.8
CVE-2022-23227 [CRITICAL] CWE-306 NUUO NVRmini2 Devices Missing Authentication Vulnerability
Vulnerability: NUUO NVRmini2 Devices Missing Authentication Vulnerability
Affected: NUUO NVRmini2 Devices
NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
Required Action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Notes: https://nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter_NVRmini-2-and-NVRsolo-series.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2022-23227
Remediation Due Date: 2025-01-08
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-23
Published