PT-2025-36934 · Ibm · Ibm Hardware Management Console - Power

·

CVE-2025-36125

·

Published

2025-09-09

·

Updated

2025-09-17

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: IBM Hardware Management Console - Power versions 10.3.1050.0 and 11.1.1110.0
Description: The IBM Hardware Management Console - Power is susceptible to a stored cross-site scripting issue. An authenticated user can inject arbitrary JavaScript code into the Web UI, potentially modifying the intended functionality and leading to credentials disclosure within a trusted session.
Recommendations: For versions 10.3.1050.0 and 11.1.1110.0, sanitize all user inputs to prevent the injection of malicious scripts.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16249
CVE-2025-36125

Affected Products

Ibm Hardware Management Console - Power