EXECUTIVE SUMMARY:
A critical vulnerability has been discovered in Jazz Team Server, which serves as the backbone of the Engineering Lifecycle Management (ELM) suite. Tracked as CVE-2025-36157 with a CVSS score of 9.8, this flaw allows unauthenticated attackers to modify key configuration files. Successful exploitation can lead to unauthorized actions, service disruption, or denial-of-service conditions. Since Jazz Team Server connects multiple products including workflow, test, and requirements management, this issue poses a broad risk across integrated systems.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical vulnerability has been discovered in Jazz Team Server, which serves as the backbone of the Engineering Lifecycle Management (ELM) suite. Tracked as CVE-2025-36157 with a CVSS score of 9.8, this flaw allows unauthenticated attackers to modify key configuration files. Successful exploitation can lead to unauthorized actions, service disruption, or denial-of-service conditions. Since Jazz Team Server connects multiple products including workflow, test, and requirements management, this issue poses a broad risk across integrated systems.[emaillocker id="1283"]
CVE-2025-36157: This vulnerability affects Jazz Team Server versions 7.0.2 through iFix035, 7.0.3 through iFix018, and 7.1.0 through iFix004. This allows an unauthenticated attacker to directly manipulate server property files, potentially leading to system instability and service disruption. Since no credentials or user interaction are required, the attack can be executed remotely with ease.
RECOMMENDATION:
We strongly recommend you upgrade IBM Jazz Team Server to version 7.0.2 iFix035-sec, 7.0.3 iFix018-sec, or 7.1.0 iFix004-sec or higher.
REFERENCES:
The following reports contain further technical details: