CVE-2025-15395 MEDIUM

CVE-2025-15395: IBM Jazz Foundation access control violation

Vendor Ibm
Product Jazz Foundation
Weakness CWE-863 · Incorrect authorization
Published February 2, 2026
Last update February 2, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.

Key dates

02Disclosure timeline

February 2, 2026 CVE published
February 2, 2026 Record updated