CVE-2024-40700: IBM Security Verify Access cross-site scripting
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Security Verify Access is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40700?
CVE-2024-40700 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-40700?
To remediate CVE-2024-40700, upgrade IBM Security Verify Access Appliance and Container to version 10.0.9 or later.
Who is affected by CVE-2024-40700?
CVE-2024-40700 affects users of IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8.
What type of attack does CVE-2024-40700 enable?
CVE-2024-40700 enables unauthenticated attackers to inject arbitrary JavaScript code into the Web UI.
Is user authentication required to exploit CVE-2024-40700?
No, CVE-2024-40700 can be exploited by unauthenticated attackers.