Authorization Token Vulnerability in IBM Jazz for Service Management
CVE-2025-36249

3.7LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
31 October 2025

What is CVE-2025-36249?

IBM Jazz for Service Management versions 1.1.3.0 to 1.1.3.25 have a vulnerability that fails to set the secure attribute on authorization tokens and session cookies. This oversight allows attackers to potentially capture cookie values through unsecured HTTP links. By crafting malicious links or embedding them in trusted websites, an attacker could intercept cookie traffic, putting sensitive session data at risk and exposing users to unauthorized access.

Affected Version(s)

Jazz for Service Management 1.1.3.0 <= 1.1.3.25

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-36249 : Authorization Token Vulnerability in IBM Jazz for Service Management