First published: Tue Sep 27 2022(Updated: )
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Application Gateway | =1.0 | |
<=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-22387.
The severity of CVE-2022-22387 is medium with a severity value of 5.4.
The affected software for CVE-2022-22387 is IBM Application Gateway version 1.0.
CVE-2022-22387 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
IBM has provided a fix for CVE-2022-22387. Please refer to the IBM support page for more information.