CVE-2025-15395
Access Control Violation in IBM Jazz Foundation 7.x Allows Unauthorized Actions
Publication date: 2026-02-02
Last updated on: 2026-02-11
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.1.0 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.1.0 |
| ibm | jazz_foundation | 7.1.0 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.0.3 |
| ibm | jazz_foundation | 7.1.0 |
| ibm | jazz_foundation | 7.1.0 |
| ibm | jazz_foundation | 7.0.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an access control violation in IBM Jazz Foundation versions 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005. It allows users to view or perform actions beyond their authorized capabilities, meaning they can access or do things they should not be able to within the system. [1]
How can this vulnerability impact me? :
The vulnerability can impact you by allowing users with low privileges to perform unauthorized actions or view information they should not have access to. This could lead to integrity issues within the system, as unauthorized changes might be made. However, it does not impact confidentiality or availability. The overall risk is considered low to moderate with a CVSS base score of 4.3. [1]
What immediate steps should I take to mitigate this vulnerability?
IBM recommends remediation by upgrading to iFix020 or later for IBM Jazz Foundation version 7.0.3 and iFix006 or later for version 7.1.0. Customers using versions below 7.0.3 should upgrade to maintenance release 7.0.3 and apply the fixes or optionally upgrade to the latest 7.2.0 version. No workarounds or mitigations are provided. [1]
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The provided resources do not specify how this vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.