CVE-2021-29712: XSS
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.
Other sources
IBM InfoSphere Information Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29712?
The severity of CVE-2021-29712 has been classified as high due to the potential for cross-site scripting attacks.
How do I fix CVE-2021-29712?
To fix CVE-2021-29712, apply the relevant patches provided by IBM for InfoSphere Information Server 11.7.
What are the consequences of CVE-2021-29712?
CVE-2021-29712 can lead to credential disclosure and unauthorized manipulation of the web user interface.
Who is affected by CVE-2021-29712?
CVE-2021-29712 affects users of IBM InfoSphere Information Server version 11.7.
Is CVE-2021-29712 a client-side or server-side vulnerability?
CVE-2021-29712 is primarily a client-side vulnerability that exploits the web interface to execute arbitrary JavaScript.