CVE-2017-1120: XSS
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1120?
CVE-2017-1120 has a medium severity rating due to its potential to disclose user credentials through cross-site scripting.
How do I fix CVE-2017-1120?
To fix CVE-2017-1120, apply the relevant patches provided by IBM for WebSphere Portal versions 8.5 and 9.0.
Which versions of IBM WebSphere Portal are affected by CVE-2017-1120?
CVE-2017-1120 affects IBM WebSphere Portal versions 8.5 and 9.0.
What type of vulnerability is CVE-2017-1120?
CVE-2017-1120 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary JavaScript code.
What are the potential risks associated with CVE-2017-1120?
The risks associated with CVE-2017-1120 include the possibility of credential disclosure while users are in a trusted session.