CVE-2025-36157
critical · 9.8IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.
9.8
CVSS
0.5%
EPSS (exploit prob.)
44th
EPSS percentile
2025-08-24
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-863
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.2 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-36157