Ibm · Ibm Websphere Application Server · CVE-2018-1643
**Name of the Vulnerable Software and Affected Versions**
IBM WebSphere Application Server versions 7.0 through 9.0
**Description**
The issue allows users to embed arbitrary JavaScript code in the Web UI, potentially altering the intended functionality and leading to credentials disclosure within a trusted session. This is due to a cross-site scripting vulnerability in the Installation Verification Tool.
**Recommendations**
For IBM WebSphere Application Server versions 7.0 through 9.0, update to a version that includes the fix for this issue to prevent cross-site scripting attacks.