CVE-2025-36397: Security vulnerabilities have been found in IBM Application Gateway
IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM Application Gateway is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36397?
CVE-2025-36397 is classified as a security vulnerability that allows for HTML injection.
How do I fix CVE-2025-36397?
To fix CVE-2025-36397, update the IBM Application Gateway to a version later than 25.09.
What versions of IBM Application Gateway are affected by CVE-2025-36397?
CVE-2025-36397 affects IBM Application Gateway versions from 23.10 to 25.09.
What type of attacks can be executed due to CVE-2025-36397?
CVE-2025-36397 can lead to remote code execution through injected malicious HTML code.
How can a user be impacted by CVE-2025-36397?
Users may be impacted by CVE-2025-36397 if they view the injected malicious content in their Web browser.