CVE-2022-35642: XSS
Published Nov 3, 2022
·Updated
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592."
Affected Software
8 affected components
IBM InfoSphere Information Server=11.7
IBM AIX
Linux Linux kernel
Microsoft Windows
All of the following
IBM InfoSphere Information Server=11.7
Any of the following
IBM AIX
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Nov 3, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-35642.
2
What is the severity of CVE-2022-35642?
The severity of CVE-2022-35642 is medium (5.4).
3
Which software is affected by CVE-2022-35642?
IBM InfoSphere Information Server 11.7 is affected by CVE-2022-35642.
4
What is the potential impact of CVE-2022-35642?
The potential impact of CVE-2022-35642 is the alteration of intended functionality and potential credentials disclosure within a trusted session.
5
How can I fix CVE-2022-35642?
To fix CVE-2022-35642, it is recommended to apply the patches or updates provided by IBM.