CVE-2017-1552: XSS
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 131396.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1552?
CVE-2017-1552 is considered a medium severity vulnerability due to its potential for exploitation.
How do I fix CVE-2017-1552?
To fix CVE-2017-1552, upgrade to a patched version of IBM InfoSphere BigInsights that addresses this vulnerability.
What types of attacks can be conducted using CVE-2017-1552?
CVE-2017-1552 can be exploited to conduct various attacks including cross-site scripting and cache poisoning.
Which versions of IBM InfoSphere BigInsights are affected by CVE-2017-1552?
CVE-2017-1552 affects IBM InfoSphere BigInsights versions 4.2.0 and 4.2.5.
Can CVE-2017-1552 be exploited remotely?
Yes, CVE-2017-1552 can be exploited remotely if a victim clicks on a specially-crafted URL.