CVE-2022-22477: XSS
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
Other sources
IBM WebSphere Application Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22477.
Which versions of IBM WebSphere Application Server are affected?
IBM WebSphere Application Server versions 8.5 and 9.0 are affected.
What is the severity of CVE-2022-22477?
The severity of CVE-2022-22477 is medium, with a severity value of 6.1.
What is the impact of the vulnerability?
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the IBM X-Force ID: 225605 and the IBM support page.