CVE-2025-15395
Unknown Unknown - Not Provided
Access Control Violation in IBM Jazz Foundation 7.x Allows Unauthorized Actions

Publication date: 2026-02-02

Last updated on: 2026-02-11

Assigner: IBM Corporation

Description
IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-02
Last Modified
2026-02-11
Generated
2026-05-07
AI Q&A
2026-02-02
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 24 associated CPEs
Vendor Product Version / Range
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.1.0
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.1.0
ibm jazz_foundation 7.1.0
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.0.3
ibm jazz_foundation 7.1.0
ibm jazz_foundation 7.1.0
ibm jazz_foundation 7.0.3
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an access control violation in IBM Jazz Foundation versions 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005. It allows users to view or perform actions beyond their authorized capabilities, meaning they can access or do things they should not be able to within the system. [1]


How can this vulnerability impact me? :

The vulnerability can impact you by allowing users with low privileges to perform unauthorized actions or view information they should not have access to. This could lead to integrity issues within the system, as unauthorized changes might be made. However, it does not impact confidentiality or availability. The overall risk is considered low to moderate with a CVSS base score of 4.3. [1]


What immediate steps should I take to mitigate this vulnerability?

IBM recommends remediation by upgrading to iFix020 or later for IBM Jazz Foundation version 7.0.3 and iFix006 or later for version 7.1.0. Customers using versions below 7.0.3 should upgrade to maintenance release 7.0.3 and apply the fixes or optionally upgrade to the latest 7.2.0 version. No workarounds or mitigations are provided. [1]


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The provided resources do not specify how this vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart