CVE-2025-36157

CRITICAL

IBM Jazz Foundation 7.0.2-7.0.3, 7.1.0 - Unauthenticated Incorrect Authorization via Server Property File Update

Title source: llm
STIX 2.1

Description

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.

References (1)

Core 1
Core References
Patch, Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7242925

Scores

CVSS v3 9.8
EPSS 0.0010
EPSS Percentile 27.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
ibm/jazz_foundation 7.0.2 (34 CPE variants)
ibm/jazz_foundation 7.0.3 (16 CPE variants)
Published Aug 24, 2025
Tracked Since Feb 18, 2026