Session Cookie Vulnerability in IBM Jazz for Service Management
CVE-2025-36011

4.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
9 September 2025

What is CVE-2025-36011?

IBM Jazz for Service Management versions 1.1.3.0 through 1.1.3.24 are vulnerable due to the lack of a secure attribute on authorization tokens and session cookies. This flaw may allow attackers to intercept cookie values by exploiting unsecured links. If a user clicks on a malicious link, their session cookies could be transmitted over an insecure channel, enabling attackers to capture sensitive information and potentially gain unauthorized access to the user's session.

Affected Version(s)

Jazz for Service Management 1.1.3.0 <= 1.1.3.24

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36011 : Session Cookie Vulnerability in IBM Jazz for Service Management