First published: Mon Aug 14 2017(Updated: )
A Cross-Site Scripting issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker may be able to upload a malicious script that attempts to redirect users to a malicious web site.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Osisoft Pi Integrator For Business Analystics | <=2016 | |
Osisoft Pi Integrator For Microsoft Azure | <=2016 | |
Osisoft Pi Integrator For Sap Hana | <=2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9655 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2017-9655, upgrade the software to a version later than 2016 R2 for PI Integrator for Business Analytics and PI Integrator for Microsoft Azure, or later than 2017 for PI Integrator for SAP HANA.
CVE-2017-9655 can be exploited through cross-site scripting, allowing attackers to inject malicious scripts.
The affected versions of OSIsoft products include PI Integrator for Business Analytics, PI Integrator for Microsoft Azure, and PI Integrator for SAP HANA before specified updates.
Yes, CVE-2017-9655 poses a risk to organizational security as it allows attackers to redirect users, potentially leading to data theft or further exploitation.