CVE-2025-23227

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
Link Resource
https://www.ibm.com/support/pages/node/7181334 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

15 Aug 2025, 12:46

Type Values Removed Values Added
Summary
  • (es) IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 a 7.3.0.11 es vulnerable a Cross-Site Scripting Almacenado. Esta vulnerabilidad permite a los usuarios autenticados incorporar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista y pudiendo provocar la divulgación de credenciales dentro de una sesión de confianza.
First Time Microsoft
Microsoft windows
Ibm
Linux
Ibm tivoli Application Dependency Discovery Manager
Ibm aix
Linux linux Kernel
References () https://www.ibm.com/support/pages/node/7181334 - () https://www.ibm.com/support/pages/node/7181334 - Vendor Advisory
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

23 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 18:15

Updated : 2025-08-15 12:46


NVD link : CVE-2025-23227

Mitre link : CVE-2025-23227

CVE.ORG link : CVE-2025-23227


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

ibm

  • aix
  • tivoli_application_dependency_discovery_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')