CVE-2025-33128
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Jun 22, 2026
Vendor
unknown
Description
IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.