Cross-Site Scripting Vulnerability in IBM WebSphere Portal
CVE-2017-1120

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
27 March 2017

Summary

The vulnerability in IBM WebSphere Portal versions 8.5 and 9.0 enables attackers to inject arbitrary JavaScript into the Web UI. This flaw allows for potential manipulation of the application's functionality, which may compromise user data by disclosing credentials within an ongoing trusted session. Organizations using affected versions should take immediate action to remediate this issue to protect against exploitation.

Affected Version(s)

WebSphere Portal 8.5.0

WebSphere Portal 9.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.