PT-2017-13811 · Ibm · Ibm Worklight Framework

Gabriele Gristina

·

Published

2017-08-01

·

Updated

2017-08-04

·

CVE-2017-1500

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Worklight Framework versions 6.1 through 8.0
Description A Reflected Cross Site Scripting (XSS) issue exists in the authorization function of the RESTful Web Api. The scope parameter is vulnerable; if its value is set to a "realm" not defined in authenticationConfig.xml, it will be reflected in the HTTP response body. This allows for the injection of arbitrary JavaScript code, potentially modifying the authorization flow and leading to credential disclosure within a trusted session.
Recommendations For IBM Worklight Framework versions 6.1 through 8.0, as a temporary workaround, consider restricting the use of the scope parameter in the authorization function until a patch is available. Avoid setting the scope parameter to arbitrary values, especially those that could be interpreted as JavaScript code, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1500

Affected Products

Ibm Worklight Framework