CVE-2017-1217: XSS
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1217?
CVE-2017-1217 has been rated as a medium severity vulnerability due to its potential impact on user sessions.
How do I fix CVE-2017-1217?
To address CVE-2017-1217, ensure that you apply the latest security patches provided by IBM for WebSphere Portal 8.5 and 9.0.
What is the impact of CVE-2017-1217?
CVE-2017-1217 can lead to cross-site scripting attacks that may allow attackers to execute arbitrary JavaScript, potentially compromising user credentials.
Which versions of WebSphere Portal are affected by CVE-2017-1217?
CVE-2017-1217 affects IBM WebSphere Portal versions 8.5 and 9.0.
Has CVE-2017-1217 been exploited in the wild?
There have been no confirmed reports of exploitation of CVE-2017-1217 in the wild, but the vulnerability should be mitigated to prevent potential attacks.