CVE-2022-22443: XSS
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224440.
Other sources
InfoSphere Information Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22443?
CVE-2022-22443 is a vulnerability in IBM InfoSphere Information Server 11.7 that allows users to inject arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
How severe is CVE-2022-22443?
CVE-2022-22443 has a severity rating of medium with a CVSS score of 5.4.
How can I fix CVE-2022-22443?
To fix CVE-2022-22443, apply the recommended patch provided by IBM. You can find the patch at the following link: [link](https://www.ibm.com/support/pages/node/878310).
What is the Common Weakness Enumeration (CWE) associated with CVE-2022-22443?
The Common Weakness Enumeration (CWE) associated with CVE-2022-22443 is CWE-79, which is a vulnerability related to improper neutralization of input during web page generation ('Cross-site Scripting').
Where can I find more information about CVE-2022-22443?
You can find more information about CVE-2022-22443 on the IBM X-Force Exchange website: [link](https://exchange.xforce.ibmcloud.com/vulnerabilities/224440) and on the IBM Support website: [link](https://www.ibm.com/support/pages/node/6575611).