CVE-2025-36157CRITICAL 9.1EPSS p42.2%
CVE-2025-36157CVE-2025-36157
Description
IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.
Scoring
| CVSS 3.1 | 9.1 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| EPSS | 0.54% probability of exploitation · percentile 42.2% · 2026-08-03T12:00:16Z |
| Published | 2025-08-24 |
| Last modified | 2025-12-18 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Authorizationcwe-863 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.