CVE-2023-30436: IBM Security Guardium cross-site scripting
IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 252292.
Other sources
IBM Security Guardium is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30436?
The severity of CVE-2023-30436 is medium (5.5).
Which versions of IBM Security Guardium are affected by CVE-2023-30436?
IBM Security Guardium versions 11.3, 11.4, and 11.5 are affected by CVE-2023-30436.
What is the impact of CVE-2023-30436 vulnerability?
The vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credential disclosure within a trusted session.
How can I fix CVE-2023-30436?
Update IBM Security Guardium to a patched version to mitigate the vulnerability.
Where can I find more information about CVE-2023-30436?
More information about CVE-2023-30436 can be found on the IBM X-Force ID: 252292 page and the IBM Support page.