Cross-Site Scripting Vulnerability in IBM Infosphere BigInsights
CVE-2016-2924

5.4MEDIUM

Key Information:

Vendor
CVE Published:
1 February 2017

Summary

IBM Infosphere BigInsights suffers from a cross-site scripting vulnerability due to improper validation of user-supplied input. This flaw allows remote attackers to craft a malicious URL that, when clicked by a user, may execute scripts in the context of the user's web browser. Exploiting this vulnerability can potentially enable attackers to steal cookie-based authentication credentials, compromising user accounts and sensitive information.

Affected Version(s)

BigInsights 3.0

BigInsights 3.0.0.1

BigInsights 3.0.0.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.