IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Advisories

No advisories yet.

Fixes

Solution

IBM encourages all customers to update their systems promptly. IBM Application Gateway (Container): Obtain the latest version of the container by running this command (without quotation marks):     “docker pull icr.io/ibmappgateway/ibm-application-gateway:[tag]”                 Where [tag] is the latest published version and can be confirmed here https://docs.verify.ibm.com/gateway/docs/containers .


Workaround

No workaround given by the vendor.

History

Tue, 20 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Title Security vulnerabilities have been found in IBM Application Gateway
First Time appeared Ibm
Ibm application Gateway
Weaknesses CWE-80
CPEs cpe:2.3:a:ibm:application_gateway:23.10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:application_gateway:23.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:application_gateway:25.09.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:application_gateway:25.09:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm application Gateway
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-01-20T15:47:24.284Z

Reserved: 2025-04-15T21:16:59.139Z

Link: CVE-2025-36397

cve-icon Vulnrichment

Updated: 2026-01-20T15:47:15.219Z

cve-icon NVD

Status : Received

Published: 2026-01-20T16:16:04.030

Modified: 2026-01-20T16:16:04.030

Link: CVE-2025-36397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses