CVE-2022-43909: IBM Security Guardium cross-site scripting
IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 240905.
Other sources
IBM Security Guardium is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-43909?
CVE-2022-43909 is a vulnerability in IBM Security Guardium 11.4 that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credential disclosure.
How severe is CVE-2022-43909?
CVE-2022-43909 has a severity score of 5.4, which is considered medium.
How does CVE-2022-43909 affect IBM Security Guardium?
CVE-2022-43909 affects IBM Security Guardium 11.4, but versions up to and including 11.5 are also affected.
How can CVE-2022-43909 be exploited?
CVE-2022-43909 can be exploited by users embedding arbitrary JavaScript code in the IBM Security Guardium Web UI.
Is there a fix for CVE-2022-43909?
Yes, IBM has provided a fix for CVE-2022-43909. Please refer to the IBM Support page for more information.