Cross-Site Scripting Vulnerability in IBM Daeja ViewONE Products
CVE-2017-1209

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
24 October 2017

Summary

IBM Daeja ViewONE products, specifically versions 4.1.5.1 and 5.0.2, exhibit a vulnerability allowing cross-site scripting. This issue permits threat actors to embed malicious JavaScript code within the Web UI, which can manipulate intended functionalities and potentially expose users' credentials during trusted sessions. As a result, it poses a significant risk to user data integrity and privacy.

Affected Version(s)

Daeja ViewONE 4.1.5.1

Daeja ViewONE 5.0.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.