First published: Wed Oct 04 2023(Updated: )
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 264019.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | =3.0.11 | |
IBM Content Navigator | =3.0.13 | |
IBM Content Navigator | =3.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-40684.
The affected software is IBM Content Navigator versions 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual.
The severity level of this vulnerability is medium with a severity value of 5.4.
The CWE of this vulnerability is CWE-79.
This vulnerability can be exploited by embedding arbitrary JavaScript code in the Web UI of IBM Content Navigator, potentially leading to credentials disclosure.