CVE-2025-33128 Details
Description
IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
A cross-site scripting vulnerability has been identified in IBM Engineering Workflow Management versions 7.0.3 prior to 7.0.3 Interim Fix 020 and 7.1 prior to 7.1 Interim Fix 007. This vulnerability allows authenticated users to inject arbitrary JavaScript into the Web UI, potentially altering functionality and leading to credential disclosure within a trusted session.
Users can upgrade to IBM Engineering Workflow Management version 7.0.3 iFix021 or 7.1 iFix008. Instructions for downloading these fixes are available on the IBM Support Fix Central website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7276116 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm engineering workflow management | 7.0.3 - 7.0.3 ifix001 7.0.3 ifix002 7.0.3 ifix003 7.0.3 ifix004 7.0.3 ifix005 7.0.3 ifix006 7.0.3 ifix007 7.0.3 ifix008 7.0.3 ifix009 7.0.3 ifix010 7.0.3 ifix011 7.0.3 ifix012 7.0.3 ifix013 7.0.3 ifix014 7.0.3 ifix015 7.0.3 ifix016 7.0.3 ifix017 7.0.3 ifix018 7.0.3 ifix019 7.0.3 ifix020 7.1.0 - 7.1.0 ifix001 7.1.0 ifix002 7.1.0 ifix003 7.1.0 ifix004 7.1.0 ifix005 7.1.0 ifix006 7.1.0 ifix007 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |