Stored Cross-Site Scripting Vulnerability in IBM WebSphere Application Server Liberty
CVE-2025-36000

4.8MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
12 August 2025

What is CVE-2025-36000?

IBM WebSphere Application Server Liberty, from version 17.0.0.3 to 25.0.0.8, contains a stored cross-site scripting vulnerability that can be exploited by a privileged user. This vulnerability allows an attacker to inject arbitrary JavaScript code into the Web User Interface. As a result, this could alter the software's intended functionality and potentially lead to the disclosure of sensitive information, including user credentials, within a trusted session.

Affected Version(s)

WebSphere Application Server Liberty 17.0.0.3 <= 25.0.0.8

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36000 : Stored Cross-Site Scripting Vulnerability in IBM WebSphere Application Server Liberty