First published: Mon Mar 27 2017(Updated: )
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000152.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =8.5 | |
IBM WebSphere Portal | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1120 has a medium severity rating due to its potential to disclose user credentials through cross-site scripting.
To fix CVE-2017-1120, apply the relevant patches provided by IBM for WebSphere Portal versions 8.5 and 9.0.
CVE-2017-1120 affects IBM WebSphere Portal versions 8.5 and 9.0.
CVE-2017-1120 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary JavaScript code.
The risks associated with CVE-2017-1120 include the possibility of credential disclosure while users are in a trusted session.