First published: Thu Feb 06 2025(Updated: )
IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | >=1.1.3<=1.1.3.23 | |
IBM Jazz for Service Management | <=1.1.3 - 1.1.3.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52892 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2024-52892, upgrade IBM Jazz for Service Management to version 1.1.3.24 or later.
The impact of CVE-2024-52892 includes the potential for an attacker to execute arbitrary JavaScript code, which may lead to credentials disclosure.
CVE-2024-52892 affects users of IBM Jazz for Service Management versions 1.1.3 through 1.1.3.23.
Yes, CVE-2024-52892 can be exploited remotely by an unauthenticated attacker.