Cross-site scripting in jquery-cookie - CVE-2022-23395
Published: March 17, 2023
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Siebel CRM Deployment
SCALANCE WAM763-1
SCALANCE WAM766-1 (EU)
SCALANCE WAM766-1 (US)
SCALANCE WAM766-1 EEC (EU)
SCALANCE WAM766-1 EEC (US)
SCALANCE WUM763-1
SCALANCE WUM766-1 (EU)
SCALANCE WUM766-1 (US)
IBM License Metric Tool
How to mitigate CVE-2022-23395
SCALANCE WAM766-1 (EU) - update to 2.0
SCALANCE WAM766-1 (US) - update to 2.0
SCALANCE WAM766-1 EEC (EU) - update to 2.0
SCALANCE WAM766-1 EEC (US) - update to 2.0
SCALANCE WUM763-1 - update to 2.0
SCALANCE WUM766-1 (EU) - update to 2.0
SCALANCE WUM766-1 (US) - update to 2.0
IBM License Metric Tool - update to 9.2.35