MEDIUM🇵🇱 Wersja polska

CVE-2025-36409

CVSS 5.4v3.1pub. 2026-01-20upd. 2026-01-26

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
  • IBM Applinx

    APP
    Ibm
    11.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-36418HIGH7.3same product

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT...

CVE-2025-36419MEDIUM5.3same product

IBM ApplinX w wersji 11.1 może ujawnić wrażliwe informacje o architekturze serwera, które mogą wspomóc dalsze ...

CVE-2025-36408MEDIUM6.4same product

IBM ApplinX 11.1 jest podatny na stored XSS. Podatność pozwala uwierzytelnionemu użytkownikowi osadzić dowolny...

CVE-2024-49793MEDIUM5.4same product

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to emb...

CVE-2024-49795MEDIUM4.3same product

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou...