CVE-2023-42009
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Dec 1, 2023
Updated: Dec 4, 2023
CWE ID 79
Summary
CVE-2023-42009 is a cross-site scripting (XSS) vulnerability affecting IBM InfoSphere Information Server 11.7. This issue allows malicious users to inject arbitrary JavaScript code into the Web UI, which can manipulate the intended functionality and potentially lead to the disclosure of credentials within a trusted session. IBM X-Force has assigned ID 265504 to this vulnerability. Users are urged to apply the recommended patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- IBM Infosphere Information Server
Affected Vendors
- IBM Corporation