First published: Thu May 31 2018(Updated: )
IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141219.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | =2.0.3 | |
IBM Content Navigator | =3.0.0 | |
IBM Content Navigator | =3.0.1 | |
IBM Content Navigator | =3.0.2 | |
IBM Content Navigator | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1496 is a vulnerability in IBM Content Navigator 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3 that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
The severity of CVE-2018-1496 is medium with a CVSS score of 5.4.
CVE-2018-1496 affects IBM Content Navigator versions 2.0.3, 3.0.0, 3.0.1, 3.0.2, and 3.0.3.
The vulnerability in IBM Content Navigator can be exploited by users embedding arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Yes, IBM has released patches and fixes to address the vulnerability in IBM Content Navigator. It is recommended to update to the latest version to mitigate the risk.