First published: Fri May 10 2024(Updated: )
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM App Connect | >=11.0.0.1<11.0.0.26 | |
IBM App Connect | >=12.0.1.0<12.0.12.1 | |
IBM App Connect | <=12.0.1.0 - 12.0.12.0 | |
IBM App Connect | <=11.0.0.1 - 11.0.0.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28761 is classified as a medium severity vulnerability due to the potential for HTML injection, which could allow remote attackers to execute malicious HTML in victims' browsers.
To fix CVE-2024-28761, users should apply the patches available from IBM for affected versions of App Connect Enterprise.
CVE-2024-28761 affects IBM App Connect Enterprise versions 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0.
CVE-2024-28761 can facilitate HTML injection attacks, allowing attackers to inject malicious HTML code that may execute in users' browsers.
Currently, there are no documented workarounds for CVE-2024-28761, so applying the recommended patches is the best course of action.