CVE-2024-28793: IBM Engineering Workflow Management cross-site scripting
IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286830.
Other sources
IBM Engineering Workflow Management is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28793?
CVE-2024-28793 is considered a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2024-28793?
To fix CVE-2024-28793, update IBM Engineering Workflow Management to the latest version beyond 7.0.3 and implement proper input validation.
What are the potential risks associated with CVE-2024-28793?
The risks of CVE-2024-28793 include unauthorized execution of JavaScript code which can lead to session hijacking and credential theft.
Which versions of IBM Engineering Workflow Management are affected by CVE-2024-28793?
IBM Engineering Workflow Management versions 7.0.2 and 7.0.3 are affected by CVE-2024-28793.
Can CVE-2024-28793 be exploited remotely?
Yes, CVE-2024-28793 can be exploited remotely by attackers who can input malicious scripts via the application’s web interface.