CVE-2023-43054

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 3, 2024
Updated: Dec 23, 2024
CWE ID 79

Summary

CVE-2023-43054 is a stored cross-site scripting (XSS) vulnerability affecting IBM Engineering Test Management versions 7.0.2 and 7.0.3. This issue permits users to inject malicious JavaScript code into the Web UI, resulting in unintended functionality alterations. Potentially, this vulnerability could lead to sensitive data, including credentials, being disclosed within a trusted session. IBM X-Force has assigned ID 267459 to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ibm Engineering Test Management

Affected Vendors

  • IBM Corporation