Cross-Site Scripting Vulnerability in IBM Daeja ViewONE Products
CVE-2017-1209
5.4MEDIUM
Summary
IBM Daeja ViewONE products, specifically versions 4.1.5.1 and 5.0.2, exhibit a vulnerability allowing cross-site scripting. This issue permits threat actors to embed malicious JavaScript code within the Web UI, which can manipulate intended functionalities and potentially expose users' credentials during trusted sessions. As a result, it poses a significant risk to user data integrity and privacy.
Affected Version(s)
Daeja ViewONE 4.1.5.1
Daeja ViewONE 5.0.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved