CVE-2022-22387: XSS
Published Sep 27, 2022
·Updated
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
2 affected components
IBM Application Gateway=1.0
IBM Application Gateway<=1.0
Remediation
Patch Available
Event History
Sep 27, 2022
CVE Published
via IBM·12:00 AM
Sep 28, 2022
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22387.
2
What is the severity of CVE-2022-22387?
The severity of CVE-2022-22387 is medium with a severity value of 5.4.
3
What is the affected software for CVE-2022-22387?
The affected software for CVE-2022-22387 is IBM Application Gateway version 1.0.
4
What is the impact of CVE-2022-22387?
CVE-2022-22387 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
5
Is there a fix available for CVE-2022-22387?
IBM has provided a fix for CVE-2022-22387. Please refer to the IBM support page for more information.