Remote Code Execution Vulnerability in IBM Jazz Foundation
CVE-2025-36157
9.8CRITICAL
What is CVE-2025-36157?
An imperative vulnerability in IBM Jazz Foundation versions 7.0.2 iFix035, 7.0.3 iFix018, and 7.1.0 iFix004 allows an unauthenticated remote attacker to manipulate server property files. This could enable the attacker to execute unauthorized actions, posing a significant risk to the integrity and security of the server. It is crucial for users to apply the necessary patches and updates to mitigate these risks and safeguard their systems.
Affected Version(s)
Engineering Lifecycle Management 7.0.2 <= 7.0.2 iFix035
Engineering Lifecycle Management 7.0.3 <= 7.0.3 iFix018
Engineering Lifecycle Management 7.1.0 <= 7.1.0 iFix004