CVE-2024-28761: IBM App Connect Enterprise HTML injection
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.
Other sources
IBM App Connect Enterprise is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28761?
CVE-2024-28761 is classified as a medium severity vulnerability due to the potential for HTML injection, which could allow remote attackers to execute malicious HTML in victims' browsers.
How do I fix CVE-2024-28761?
To fix CVE-2024-28761, users should apply the patches available from IBM for affected versions of App Connect Enterprise.
What versions of IBM App Connect Enterprise are affected by CVE-2024-28761?
CVE-2024-28761 affects IBM App Connect Enterprise versions 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0.
What types of attacks can CVE-2024-28761 facilitate?
CVE-2024-28761 can facilitate HTML injection attacks, allowing attackers to inject malicious HTML code that may execute in users' browsers.
Is there a workaround for CVE-2024-28761 if I cannot apply a patch immediately?
Currently, there are no documented workarounds for CVE-2024-28761, so applying the recommended patches is the best course of action.