CVE-2025-36397
MEDIUMIBM Application Gateway < 25.09 - Basic XSS
Title source: ruleDescription
IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Scores
CVSS v3
5.4
EPSS
0.0004
EPSS Percentile
11.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-80
Status
published
Affected Products (1)
ibm/application_gateway
< 25.09
Timeline
Published
Jan 20, 2026
Tracked Since
Feb 18, 2026