CVE-2025-36000: IBM WebSphere Application Server Liberty cross-site scripting
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.8
is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 25.0.0.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH67546
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36000?
The severity of CVE-2025-36000 is classified as high due to its potential impact on user credentials and application functionality.
How do I fix CVE-2025-36000?
To fix CVE-2025-36000, upgrade your IBM WebSphere Application Server Liberty to version 25.0.0.9 or later.
Who is affected by CVE-2025-36000?
Users of IBM WebSphere Application Server Liberty versions 17.0.0.3 through 25.0.0.8 are affected by CVE-2025-36000.
What type of vulnerability is CVE-2025-36000?
CVE-2025-36000 is a stored cross-site scripting (XSS) vulnerability.
What can attackers achieve with CVE-2025-36000?
Attackers exploiting CVE-2025-36000 can embed arbitrary JavaScript code in the Web UI, potentially compromising user credentials.