HIGH🇵🇱 Wersja polska

CVE-2025-36418

CVSS 7.3v3.1pub. 2026-01-20upd. 2026-01-26

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to craft or modify a JSON web token in order to impersonate another user or to elevate their privileges.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • IBM Applinx

    APP
    Ibm
    11.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2025-36419MEDIUM5.3same product

IBM ApplinX w wersji 11.1 może ujawnić wrażliwe informacje o architekturze serwera, które mogą wspomóc dalsze ...

CVE-2025-36409MEDIUM5.4same product

IBM ApplinX 11.1 jest podatny na cross-site scripting (XSS). Ta podatność pozwala uwierzytelnionemu użytkownik...

CVE-2025-36408MEDIUM6.4same product

IBM ApplinX 11.1 jest podatny na stored XSS. Podatność pozwala uwierzytelnionemu użytkownikowi osadzić dowolny...

CVE-2024-49793MEDIUM5.4same product

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to emb...

CVE-2024-49795MEDIUM4.3same product

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou...