First published: Tue Jan 31 2023(Updated: )
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245423.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.7 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Ibm Infosphere Information Server | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23475 is medium.
CVE-2023-23475 allows users to embed arbitrary JavaScript code in the Web UI of IBM Infosphere Information Server 11.7, potentially leading to credentials disclosure.
No, IBM AIX is not affected by CVE-2023-23475.
No, Linux Linux kernel is not affected by CVE-2023-23475.
To fix CVE-2023-23475 vulnerability, apply the patch provided by IBM at the following URL: https://www.ibm.com/support/pages/node/878310.