CVE-2017-1203: XSS
IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123678.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1203?
The severity of CVE-2017-1203 is rated as medium due to the potential impact on user credentials and application functionality.
How do I fix CVE-2017-1203?
To fix CVE-2017-1203, it is recommended to apply the latest patches provided by IBM for the affected versions of the IBM BigFix Platform.
What versions are affected by CVE-2017-1203?
CVE-2017-1203 affects multiple versions of IBM BigFix Platform, including versions 9.1.x, 9.2.x, and 9.5.x.
What type of vulnerability is CVE-2017-1203?
CVE-2017-1203 is a cross-site scripting (XSS) vulnerability that allows attackers to embed arbitrary JavaScript in the web interface.
Can CVE-2017-1203 lead to credential disclosure?
Yes, CVE-2017-1203 may lead to credential disclosure as it allows attackers to manipulate the Web UI and potentially capture user information.