Ibm · Ibm Spectrum Symphony · CVE-2018-1706
**Name of the Vulnerable Software and Affected Versions**
IBM Spectrum Symphony version 7.2.0.2
**Description**
The issue allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session.
**Recommendations**
For IBM Spectrum Symphony version 7.2.0.2, consider disabling the Web UI functionality until a patch is available to prevent potential cross-site scripting attacks.