Metrics
Affected Vendors & Products
No advisories yet.
Solution
Remediation/Fixes Affected endpoint have been updated to sanitise input parameters to align with security best practices. A fix has been created for each affected version of the named product. Download and install the fix as soon as possible. Fixes and installation instructions are provided at the URLs listed below: Product Remediation For IBM OpenPages 9.1.2 Download URL for 9.1.2 https://www.ibm.com/support/pages/downloading-ibm-openpages-version-912-passport-advantage For IBM OpenPages 9.0 - Apply 9.0 FixPack 5 (9.0.0.5) - Then Apply 9.0.05 Interim Fix 5 ( 9.0.0.5.6 ) Download URL for 9.0.0.5 https://www.ibm.com/support/pages/ibm-openpages-90-fix-pack-5 Download URL for 9.0.0.5.6 https://www.ibm.com/support/pages/ibm-openpages-9005-interim-fix-6 For IBM OpenPages v8.0/8.1/8.2/8.3 customers, IBM recommends to upgrade to a fixed and supported version 9.0 or 9.1.2 of the product.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7248932 |
|
Mon, 27 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm openpages |
|
| CPEs | cpe:2.3:a:ibm:openpages:9.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:openpages:9.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm openpages |
Mon, 27 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Title | HTML Injection Vulnerability in a Specific URL Endpoint of the IBM OpenPages Application | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-10-27T18:51:26.399Z
Reserved: 2025-04-15T21:16:18.171Z
Link: CVE-2025-36121
Updated: 2025-10-27T15:17:38.151Z
Status : Received
Published: 2025-10-27T15:15:38.473
Modified: 2025-10-27T15:15:38.473
Link: CVE-2025-36121
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:03:49Z