PT-2025-34545 · Ibm · Ibm Jazz Foundation

CVE-2025-36157

·

Published

2025-08-24

·

Updated

2025-12-18

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: IBM Jazz Foundation versions 7.0.2 through 7.0.2 iFix035 IBM Jazz Foundation versions 7.0.3 through 7.0.3 iFix018 IBM Jazz Foundation versions 7.1.0 through 7.1.0 iFix004
Description: The vulnerability allows an unauthenticated remote attacker to update server property files, potentially enabling unauthorized actions.
Recommendations: IBM Jazz Foundation versions prior to 7.0.2 iFix035 should be updated. IBM Jazz Foundation versions prior to 7.0.3 iFix018 should be updated. IBM Jazz Foundation versions prior to 7.1.0 iFix004 should be updated.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00228
CVE-2025-36157

Affected Products

Ibm Jazz Foundation