Cross-site scripting in IBM WebSphere Application Server - CVE-2023-24966

 

Cross-site scripting in IBM WebSphere Application Server - CVE-2023-24966

Published: April 26, 2023


Vulnerability identifier: #VU75531
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2023-24966
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the Web UI. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

IBM WebSphere Application Server
IBM Workload Scheduler
Jazz for Service Management
IBM Operations Analytics Predictive Insights
WebSphere Remote Server
IBM Intelligent Operations Center
IBM Tivoli Monitoring
Engineering Test Management
Business Monitor

How to mitigate CVE-2023-24966

Install updates from vendor's website.

IBM Intelligent Operations Center - update to 5.2.3
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5

External References

Related Security Bulletins