CVE-2024-45087
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 79
Summary
CVE-2024-45087 is a newly disclosed cross-site scripting (XSS) vulnerability affecting IBM WebSphere Application Server versions 8.5 and 9.0. A privileged user can exploit this flaw to inject malicious JavaScript code into the Web UI, altering its intended functionality. This could potentially result in sensitive data, including credentials, being disclosed during a trusted session. IBM has released patches to address this issue, and users are strongly advised to apply them promptly to mitigate the risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- IBM WebSphere Application Server
Affected Vendors
- IBM Corporation