CVE-2025-36396
EUVD-2026-336820.01.2026, 16:16
IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | application_gateway | 23.10 ≤ 𝑥 ≤ 25.09 |
𝑥
= Vulnerable software versions