CVE-2022-34358: XSS
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.
Other sources
IBM i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this cross-site scripting vulnerability?
The vulnerability ID of this cross-site scripting vulnerability is CVE-2022-34358.
Which versions of IBM i are affected by this vulnerability?
IBM i 7.5, 7.4, 7.3, and 7.2 are affected by this vulnerability.
What is the potential impact of this vulnerability?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium, with a CVSS score of 5.4.
How can I fix this cross-site scripting vulnerability in IBM i?
To fix this vulnerability, it is recommended to apply the latest security patches and updates from IBM.