Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-27481 | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
Solution
The following fixes are available on IBM Fix Central at: http://www-933.ibm.com/support/fixcentral/ Product VRMF APAR Remediation/Fix Power HMC V10.3.1060.0 SP2 x86 MB04499 MF71734 Power HMC V10.3.1060.0 SP2 ppc MB04500 MF71735 Power HMC V11.1.1110.0 x86 MB04497 MF71732 Power HMC V11.1.1110.0 ppc MB04498 MF71733
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7244336 |
![]() ![]() |
Tue, 09 Sep 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 09 Sep 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
Title | IBM Hardware Management Console - Power Systems cross-site scripting | |
First Time appeared |
Ibm
Ibm power Hardware Management Console |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:ibm:power_hardware_management_console:10.3.1050.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:power_hardware_management_console:11.1.1110.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm power Hardware Management Console |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-09T19:41:48.323Z
Reserved: 2025-04-15T21:16:18.171Z
Link: CVE-2025-36125

Updated: 2025-09-09T19:41:17.483Z

Status : Awaiting Analysis
Published: 2025-09-09T20:15:39.280
Modified: 2025-09-11T17:14:25.240
Link: CVE-2025-36125

No data.

No data.