CVE-2025-36173: InfoSphere Data Architect (IDA) 9.2.1 Vulnerability Fixes.
Affected Product(s)Version(s)InfoSphere Data Architect9.2.1
Other sources
IBM InfoSphere Data Architect is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36173?
CVE-2025-36173 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-36173?
To fix CVE-2025-36173, users should upgrade to a patched version of IBM InfoSphere Data Architect that addresses this vulnerability.
What kind of attack does CVE-2025-36173 allow?
CVE-2025-36173 allows an unauthenticated attacker to execute arbitrary JavaScript code within the web UI.
Which versions of IBM InfoSphere Data Architect are affected by CVE-2025-36173?
IBM InfoSphere Data Architect version 9.2.1 is affected by CVE-2025-36173.
Can CVE-2025-36173 be exploited without authentication?
Yes, CVE-2025-36173 can be exploited by unauthenticated attackers.