IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27481 IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Fixes

Solution

The following fixes are available on IBM Fix Central at: http://www-933.ibm.com/support/fixcentral/ Product VRMF APAR Remediation/Fix Power HMC V10.3.1060.0 SP2 x86 MB04499 MF71734 Power HMC V10.3.1060.0 SP2 ppc MB04500 MF71735 Power HMC V11.1.1110.0 x86 MB04497 MF71732 Power HMC V11.1.1110.0 ppc MB04498 MF71733


Workaround

No workaround given by the vendor.

History

Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 19:45:00 +0000

Type Values Removed Values Added
Description IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Hardware Management Console - Power Systems cross-site scripting
First Time appeared Ibm
Ibm power Hardware Management Console
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:power_hardware_management_console:10.3.1050.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_hardware_management_console:11.1.1110.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Hardware Management Console
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-09T19:41:48.323Z

Reserved: 2025-04-15T21:16:18.171Z

Link: CVE-2025-36125

cve-icon Vulnrichment

Updated: 2025-09-09T19:41:17.483Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T20:15:39.280

Modified: 2025-09-11T17:14:25.240

Link: CVE-2025-36125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.