First published: Thu Jul 27 2023(Updated: )
IBM B2B Advanced Communication is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Advanced Communications | >=1.0<1.0.0.8 | |
IBM Multi-Enterprise Integration Gateway | =1.0.0.1 | |
<=1.0.0.x | ||
<=1.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22595 is classified as a cross-site scripting vulnerability which can lead to credential disclosure in trusted sessions.
To fix CVE-2023-22595, update IBM B2B Advanced Communications to version 1.0.0.8 or later.
CVE-2023-22595 affects IBM B2B Advanced Communications versions earlier than 1.0.0.8 and IBM Multi-Enterprise Integration Gateway version 1.0.0.1.
CVE-2023-22595 allows attackers to execute arbitrary JavaScript code within the web UI of affected systems.
Yes, CVE-2023-22595 can be exploited remotely by injecting scripts through the web interface.