CVE-2017-1739: XSS
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134921.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1739?
CVE-2017-1739 is a vulnerability in IBM Curam Social Program Management that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
What is the severity of CVE-2017-1739?
The severity of CVE-2017-1739 is medium, with a CVSS score of 5.4.
How does CVE-2017-1739 impact IBM Curam Social Program Management?
CVE-2017-1739 allows attackers to carry out cross-site scripting attacks on IBM Curam Social Program Management, potentially leading to credentials disclosure within a trusted session.
Is there a fix available for CVE-2017-1739?
Yes, IBM has released patches to address the vulnerability in different versions of IBM Curam Social Program Management. Please refer to the IBM Security Bulletin for more information.
Where can I find more information about CVE-2017-1739?
You can find more information about CVE-2017-1739 in the IBM Security Bulletin, SecurityFocus, and IBM X-Force Exchange.