Junglewise Threat Intelligence

CVE-2025-33128: IBM Engineering Workflow Management cross-site scripting in Web UI

CVE-2025-33128 · Severity: medium · CVSS 5.4 · Published 2026-06-22

Vendors: IBM.

Executive brief

IBM Engineering Workflow Management, a tool used by software teams to manage tasks and source code, is affected by a security flaw that allows malicious scripts to be injected into its web interface. An attacker with basic user access could use this to trick other users into running harmful code, potentially leading to the theft of login credentials or unauthorized actions within the platform. Organizations should apply the latest interim fixes to protect their development environments.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Web UI of IBM Engineering Workflow Management versions 7.0.3 and 7.1. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can exploit this by embedding arbitrary JavaScript code that executes in the context of another user's browser session when they visit a compromised page. This can lead to the disclosure of sensitive information, such as session credentials, or the alteration of intended application functionality. IBM has released remediation via 7.0.3 iFix021 and 7.1.0 iFix008.

Affected products

  • IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, 7.1 through 7.1 Interim Fix 007

Timeline

  • 2026-06-12: advisory: Initial publication by IBM
  • 2026-06-22: disclosed: NVD publication date

References

Related threats