Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27481 | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
Solution
The following fixes are available on IBM Fix Central at: http://www-933.ibm.com/support/fixcentral/ Product VRMF APAR Remediation/Fix Power HMC V10.3.1060.0 SP2 x86 MB04499 MF71734 Power HMC V10.3.1060.0 SP2 ppc MB04500 MF71735 Power HMC V11.1.1110.0 x86 MB04497 MF71732 Power HMC V11.1.1110.0 ppc MB04498 MF71733
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7244336 |
|
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM Hardware Management Console - Power Systems cross-site scripting | |
| First Time appeared |
Ibm
Ibm power Hardware Management Console |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:power_hardware_management_console:10.3.1050.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_hardware_management_console:11.1.1110.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm power Hardware Management Console |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-09T19:41:48.323Z
Reserved: 2025-04-15T21:16:18.171Z
Link: CVE-2025-36125
Updated: 2025-09-09T19:41:17.483Z
Status : Awaiting Analysis
Published: 2025-09-09T20:15:39.280
Modified: 2025-09-11T17:14:25.240
Link: CVE-2025-36125
No data.
OpenCVE Enrichment
No data.
EUVD