Stored Cross-Site Scripting Vulnerability in IBM Hardware Management Console
CVE-2025-36125

6.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
9 September 2025

What is CVE-2025-36125?

The IBM Hardware Management Console is susceptible to a stored cross-site scripting vulnerability that permits authenticated users to inject arbitrary JavaScript code within the Web UI. This malicious code can compromise the intended functionality of the interface and may expose sensitive user credentials during trusted sessions. Proper mitigation strategies should be implemented to safeguard against this vulnerability.

Affected Version(s)

Hardware Management Console 10.3.1050.0

Hardware Management Console 11.1.1110.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36125 : Stored Cross-Site Scripting Vulnerability in IBM Hardware Management Console