PT-2025-34545 · Ibm · Ibm Jazz Foundation

Published

2025-08-24

·

Updated

2025-12-18

·

CVE-2025-36157

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: IBM Jazz Foundation versions 7.0.2 through 7.0.2 iFix035 IBM Jazz Foundation versions 7.0.3 through 7.0.3 iFix018 IBM Jazz Foundation versions 7.1.0 through 7.1.0 iFix004
Description: The vulnerability allows an unauthenticated remote attacker to update server property files, potentially enabling unauthorized actions.
Recommendations: IBM Jazz Foundation versions prior to 7.0.2 iFix035 should be updated. IBM Jazz Foundation versions prior to 7.0.3 iFix018 should be updated. IBM Jazz Foundation versions prior to 7.1.0 iFix004 should be updated.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-00228
CVE-2025-36157

Affected Products

Ibm Jazz Foundation