IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7242925 |
|
History
Tue, 26 Aug 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | IBM Jazz Foundation incorrect authorization | IBM Engineering Lifecycle Management incorrect authorization |
Mon, 25 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 24 Aug 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions. | |
| Title | IBM Jazz Foundation incorrect authorization | |
| First Time appeared |
Ibm
Ibm jazz Foundation |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ibm:jazz_foundation:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.0.2:ifix035:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.0.3:ifix018:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_foundation:7.1.0:ifix004:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm jazz Foundation |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2025-08-24T01:14:41.359Z
Updated: 2025-08-26T14:46:31.452Z
Reserved: 2025-04-15T21:16:20.813Z
Link: CVE-2025-36157
Updated: 2025-08-25T11:34:51.711Z
Status : Awaiting Analysis
Published: 2025-08-24T02:15:44.100
Modified: 2025-08-25T20:24:45.327
Link: CVE-2025-36157
No data.