CVE-2017-1290: XSS
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125151.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1290?
CVE-2017-1290 has a medium severity level due to the potential for cross-site scripting attacks that could lead to credential disclosure.
How do I fix CVE-2017-1290?
To fix CVE-2017-1290, IBM recommends upgrading to a patched version of the IBM OpenPages GRC Platform that addresses this vulnerability.
What versions of IBM OpenPages GRC Platform are affected by CVE-2017-1290?
CVE-2017-1290 affects IBM OpenPages GRC Platform versions 7.1, 7.2, and 7.3.
What types of attacks can exploit CVE-2017-1290?
CVE-2017-1290 can be exploited through cross-site scripting (XSS), allowing attackers to inject arbitrary JavaScript into the web application.
Is user data at risk with CVE-2017-1290?
Yes, user data, including credentials, may be at risk due to possible exploitation of the cross-site scripting vulnerability.