IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27481 IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Fixes

Solution

The following fixes are available on IBM Fix Central at: http://www-933.ibm.com/support/fixcentral/ Product VRMF APAR Remediation/Fix Power HMC V10.3.1060.0 SP2 x86 MB04499 MF71734 Power HMC V10.3.1060.0 SP2 ppc MB04500 MF71735 Power HMC V11.1.1110.0 x86 MB04497 MF71732 Power HMC V11.1.1110.0 ppc MB04498 MF71733


Workaround

No workaround given by the vendor.

History

Fri, 19 Dec 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm hardware Management Console
CPEs cpe:2.3:a:ibm:hardware_management_console:10.3.1050.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:hardware_management_console:11.1.1110.0:*:*:*:*:*:*:*
Vendors & Products Ibm hardware Management Console

Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 19:45:00 +0000

Type Values Removed Values Added
Description IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Hardware Management Console - Power Systems cross-site scripting
First Time appeared Ibm
Ibm power Hardware Management Console
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:power_hardware_management_console:10.3.1050.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:power_hardware_management_console:11.1.1110.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm power Hardware Management Console
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-09-09T19:41:48.323Z

Reserved: 2025-04-15T21:16:18.171Z

Link: CVE-2025-36125

cve-icon Vulnrichment

Updated: 2025-09-09T19:41:17.483Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-09T20:15:39.280

Modified: 2025-12-19T14:38:50.407

Link: CVE-2025-36125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses