Cross-Site Scripting Vulnerability in IBM Jazz Foundation Web Interface
CVE-2024-43184

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2025

What is CVE-2024-43184?

The IBM Jazz Foundation product is susceptible to a cross-site scripting vulnerability that affects specific versions of its web interface. This flaw permits unauthenticated attackers to inject arbitrary JavaScript code into the user interface. As a result, the functionality of the application can be compromised, leading to potential credential disclosures even within trusted user sessions. Addressing this vulnerability is crucial to maintaining the integrity and security of user data.

Affected Version(s)

Jazz Foundation 7.0.2 <= 7.0.2 iFix033

Jazz Foundation 7.0.3 <= 7.0.3 iFix012

Jazz Foundation 7.1.0 <= 7.1.0 iFix002

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.