First published: Wed Apr 27 2022(Updated: )
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218370.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.7 | |
IBM InfoSphere Information Server, Information Server on Cloud | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-22322.
CVE-2022-22322 has a severity rating of 5.4, which is considered medium.
The affected software is IBM InfoSphere Information Server version 11.7.
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
To fix the vulnerability, apply the patch provided by IBM at the following URL: https://www.ibm.com/support/pages/node/878310