Stored Cross-Site Scripting Vulnerability in IBM InfoSphere Master Data Management
CVE-2023-46187
5.4MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 27 January 2025
Summary
IBM InfoSphere Master Data Management versions 11.6, 12.0, and 14.0 are vulnerable to stored cross-site scripting issues. This flaw enables attackers to inject arbitrary JavaScript into the web interface, potentially compromising user sessions by altering functionality and resulting in the leakage of sensitive credentials. Users interacting with the affected application may unknowingly execute malicious scripts, making it crucial for organizations to address this vulnerability promptly.
Affected Version(s)
InfoSphere Master Data Management 11.6, 12.0, 14.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved