First published: Tue Mar 26 2024(Updated: )
IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in a specially crafted URI. IBM X-Force ID: 284576.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27270 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To patch CVE-2024-27270, you should update IBM WebSphere Application Server Liberty to the latest version as recommended in the vendor's security advisory.
CVE-2024-27270 affects IBM WebSphere Application Server Liberty versions 23.0.0.3 through 24.0.0.3.
CVE-2024-27270 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject and execute arbitrary JavaScript code.
The vendor responsible for CVE-2024-27270 is IBM, specifically regarding their WebSphere Application Server Liberty product.