Authorization Token Vulnerability in IBM Jazz for Service Management
CVE-2025-36249 
3.7LOW
What is CVE-2025-36249?
IBM Jazz for Service Management versions 1.1.3.0 to 1.1.3.25 have a vulnerability that fails to set the secure attribute on authorization tokens and session cookies. This oversight allows attackers to potentially capture cookie values through unsecured HTTP links. By crafting malicious links or embedding them in trusted websites, an attacker could intercept cookie traffic, putting sensitive session data at risk and exposing users to unauthorized access.
Affected Version(s)
Jazz for Service Management 1.1.3.0 <= 1.1.3.25