Metrics
Affected Vendors & Products
No advisories yet.
Solution
Remediation/Fixes Affected JazzSM Version Recommended Fix Jazz for Service Management version 1.1.3.0 - 1.1.3.25 Install JazzSM 1.1.3.26: 1.1.3-TIV-JazzSM-multi-FP026
Workaround
No workaround given by the vendor.
| Link | Providers | 
|---|---|
| https://www.ibm.com/support/pages/node/7249820 |     | 
Fri, 31 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 31 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. | |
| Title | IBM Jazz for Service Management is vulnerable to "filter" cookie not sent over SSL | |
| First Time appeared | Ibm Ibm jazz For Service Management | |
| Weaknesses | CWE-614 | |
| CPEs | cpe:2.3:a:ibm:jazz_for_service_management:1.1.3.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:jazz_for_service_management:1.1.3.25:*:*:*:*:*:*:* | |
| Vendors & Products | Ibm Ibm jazz For Service Management | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-10-31T13:43:40.821Z
Reserved: 2025-04-15T21:16:43.936Z
Link: CVE-2025-36249
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-31T13:43:32.783Z
 NVD
                        NVD
                    Status : Received
Published: 2025-10-31T13:15:33.823
Modified: 2025-10-31T13:15:33.823
Link: CVE-2025-36249
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.