CVE-2025-36396: Security vulnerabilities have been found in IBM Application Gateway
IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36396?
CVE-2025-36396 is categorized as a high severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2025-36396?
To fix CVE-2025-36396, upgrade IBM Application Gateway to a version beyond 25.09.
Who is affected by CVE-2025-36396?
CVE-2025-36396 affects IBM Application Gateway versions from 23.10 to 25.09.
What type of vulnerability is CVE-2025-36396?
CVE-2025-36396 is a cross-site scripting (XSS) vulnerability.
Can CVE-2025-36396 be exploited by unauthenticated users?
No, CVE-2025-36396 requires the attacker to be an authenticated user to exploit the vulnerability.