Cross-site scripting in IBM WebSphere Application Server - CVE-2022-40750
Published: November 2, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the Admin Console when using the Application Migration Report function. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Workload Scheduler
IBM Tivoli Monitoring
Jazz for Service Management
IBM Tivoli System Automation Application Manager
How to mitigate CVE-2022-40750
External References
Related Security Bulletins
- XSS in IBM WebSphere Application Server Admin Console
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Cross-site scripting in IBM Tivoli Netcool/OMNIbus WebGUI
- XSS in Jazz for Service Management (JazzSM)
- Cross-site scripting in IBM WebSphere Application Server
- Cross-site scripting in IBM Tivoli System Automation Application Manager