First published: Tue May 01 2018(Updated: )
IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141338.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Manager Enterprise | =8.4.3 | |
IBM Content Manager Enterprise | =8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-1502.
The severity level of CVE-2018-1502 is medium.
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI of IBM Content Manager Enterprise Edition Resource Manager 8.4.3 and 9.5, potentially leading to credentials disclosure within a trusted session.
An attacker can exploit this vulnerability by embedding arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially disclosing credentials within a trusted session.
Yes, IBM has released patches and workaround details to address this vulnerability. Please refer to the official IBM security bulletin for more information.