Skip to main content

Vendor/product archive

ibm / applinx CVEs

Beta · best-effort

15 CVEs tagged to ibm / applinx0 Critical, 1 High, 12 Medium, 2 Low, 0 Unrated.

CVE-2025-36419

Published Jan 20, 2026

IBM ApplinX 11.1 could disclose sensitive information about server architecture that could aid in further attacks against the system.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36418

Published Jan 20, 2026

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to craft or modify a JSON web token…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36411

Published Jan 20, 2026

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-36410

Published Jan 20, 2026

IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-36409

Published Jan 20, 2026

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36408

Published Jan 20, 2026

IBM ApplinX 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the i…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49800

Published Feb 6, 2025

IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49798

Published Feb 6, 2025

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49797

Published Feb 6, 2025

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49796

Published Feb 6, 2025

IBM ApplinX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49795

Published Feb 6, 2025

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49794

Published Feb 6, 2025

IBM ApplinX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49793

Published Feb 6, 2025

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49792

Published Feb 6, 2025

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49791

Published Feb 6, 2025

IBM ApplinX 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1