CVE-2025-36157

Severity
9.1CRITICAL
EPSS
0.1%
top 77.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24

Description

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDibm/jazz_foundation7.0.2, 7.0.3, 7.1.0+2
CVEListV5ibm/engineering_lifecycle_management7.0.27.0.2 iFix035+2

Patches

🔴Vulnerability Details

2
CVEList
IBM Engineering Lifecycle Management incorrect authorization2025-08-24
GHSA
GHSA-7hxx-86w9-pq4x: IBM Jazz Foundation 72025-08-24