PT-2026-5896 · Ibm · Engineering Lifecycle Management - Global Configuration Management

Published

2026-02-03

·

Updated

2026-02-25

·

CVE-2025-36033

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Engineering Lifecycle Management - Global Configuration Management versions 7.0.3 through 7.0.3 Interim Fix 017 IBM Engineering Lifecycle Management - Global Configuration Management versions 7.1.0 through 7.1.0 Interim Fix 004
Description The software is susceptible to a cross-site scripting issue. An authenticated user can inject arbitrary JavaScript code into the Web UI, potentially modifying the intended functionality and leading to credentials disclosure within a trusted session.
Recommendations Apply Interim Fix 018 or later for versions 7.0.3. Apply Interim Fix 005 or later for versions 7.1.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-36033

Affected Products

Engineering Lifecycle Management - Global Configuration Management