CVE-2024-39728: IBM Datacap Navigator cross-site scripting
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 295967.
Other sources
IBM Datacap Navigator is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39728?
The severity of CVE-2024-39728 is classified as high due to its potential for credential disclosure through stored cross-site scripting.
How do I fix CVE-2024-39728?
To fix CVE-2024-39728, upgrade to the latest version of IBM Datacap Navigator or apply the necessary security patches provided by IBM.
What versions of IBM Datacap are affected by CVE-2024-39728?
CVE-2024-39728 affects IBM Datacap versions 9.1.5 through 9.1.9.
Is IBM Datacap Navigator vulnerable due to CVE-2024-39728?
Yes, IBM Datacap Navigator versions 9.1.5 through 9.1.9 are vulnerable due to CVE-2024-39728.
What type of vulnerability is CVE-2024-39728?
CVE-2024-39728 is a stored cross-site scripting (XSS) vulnerability.