Metrics
Affected Vendors & Products
Solution
IBM recommends addressing the vulnerability in a timely manner. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Copy Services Manager6.3.14Download v6.3.14 https://www.ibm.com/support/pages/node/7229201/stub and follow release notes https://www.ibm.com/support/pages/system/files/inline-files/csm_release_notes_6_3_14.pdf
Workaround
1) Locate the server.xml file under the csmServer 2) Create a backup of the file 3) Edit the file and locate the line <httpSession cookieSecure="true" cookieName="csmsessionid" cookieSameSite="Lax" /> 4) Change the line to the following: <httpSession cookieSecure="true" cookieName="csmsessionid" cookieSameSite="Strict" /> 5) Restart IBM Copy Services Manager service.
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7245562 |
![]() ![]() |
Fri, 19 Sep 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 19 Sep 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
Title | IBM Copy Services Manager cross-site scripting | |
First Time appeared |
Ibm
Ibm copy Services Manager |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:ibm:copy_services_manager:6.3.13:*:*:*:*:*:*:* | |
Vendors & Products |
Ibm
Ibm copy Services Manager |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-19T16:50:59.984Z
Reserved: 2025-04-15T21:16:43.936Z
Link: CVE-2025-36248

Updated: 2025-09-19T16:50:53.141Z

Status : Received
Published: 2025-09-19T17:15:46.267
Modified: 2025-09-19T17:15:46.267
Link: CVE-2025-36248

No data.

No data.