CVE-2023-25928: IBM InfoSphere Information Server cross-site scripting
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247646.
Other sources
IBM InfoSphere Information Server is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-25928.
What is the severity of CVE-2023-25928?
The severity of CVE-2023-25928 is medium (CVSS score: 5.4).
How does this vulnerability affect IBM InfoSphere Information Server?
IBM InfoSphere Information Server version 11.7 is affected by this vulnerability.
How can I fix CVE-2023-25928?
You can fix CVE-2023-25928 by applying the patch provided by IBM. The patch can be downloaded from the following URL: [https://www.ibm.com/support/pages/node/878310](https://www.ibm.com/support/pages/node/878310)
Is IBM AIX affected by CVE-2023-25928?
No, IBM AIX is not affected by CVE-2023-25928.