Cross-Site Scripting Vulnerability in IBM Infosphere BigInsights
CVE-2016-2924
5.4MEDIUM
Summary
IBM Infosphere BigInsights suffers from a cross-site scripting vulnerability due to improper validation of user-supplied input. This flaw allows remote attackers to craft a malicious URL that, when clicked by a user, may execute scripts in the context of the user's web browser. Exploiting this vulnerability can potentially enable attackers to steal cookie-based authentication credentials, compromising user accounts and sensitive information.
Affected Version(s)
BigInsights 3.0
BigInsights 3.0.0.1
BigInsights 3.0.0.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved