First published: Wed Aug 29 2018(Updated: )
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121152.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Campaign | =9.1 | |
IBM Campaign | =9.1.2 | |
IBM Campaign | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1114 is considered a high severity vulnerability due to its potential for cross-site scripting and credential disclosure.
To fix CVE-2017-1114, you should update IBM Campaign to the latest patched version available from IBM.
CVE-2017-1114 affects IBM Campaign versions 9.1, 9.1.2, and 10.0.
A cross-site scripting vulnerability allows an attacker to inject arbitrary JavaScript into a web application, which can then execute in the context of other users.
Yes, CVE-2017-1114 can potentially lead to data breaches by allowing attackers to capture sensitive information such as user credentials in trusted sessions.