CVE-2017-1549: XSS
Published Dec 11, 2017
·Updated
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.
Affected Software
1 affected component
IBM Sterling File Gateway=2.2
Event History
Dec 11, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-1549.
2
What is the severity of the vulnerability?
The severity of the vulnerability is medium.
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
4
What is the affected software for this vulnerability?
The affected software for this vulnerability is IBM Sterling File Gateway 2.2.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by embedding arbitrary JavaScript code in the Web UI of IBM Sterling File Gateway 2.2.