First published: Wed Apr 27 2022(Updated: )
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224440.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.7 | |
IBM InfoSphere Information Server,Information Server on Cloud | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22443 is a vulnerability in IBM InfoSphere Information Server 11.7 that allows users to inject arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
CVE-2022-22443 has a severity rating of medium with a CVSS score of 5.4.
To fix CVE-2022-22443, apply the recommended patch provided by IBM. You can find the patch at the following link: [link](https://www.ibm.com/support/pages/node/878310).
The Common Weakness Enumeration (CWE) associated with CVE-2022-22443 is CWE-79, which is a vulnerability related to improper neutralization of input during web page generation ('Cross-site Scripting').
You can find more information about CVE-2022-22443 on the IBM X-Force Exchange website: [link](https://exchange.xforce.ibmcloud.com/vulnerabilities/224440) and on the IBM Support website: [link](https://www.ibm.com/support/pages/node/6575611).