PT-2024-4810 · Ibm · Ibm Security Guardium
Published
2024-05-23
·
Updated
2025-01-08
·
CVE-2023-47710
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Security Guardium versions 11.4 through 12.0
Description:
The issue exists due to insufficient protection of the web page structure, allowing a remote attacker to exploit it and potentially disclose credentials within a trusted session. This is made possible by the ability to embed arbitrary JavaScript code in the Web UI, altering its intended functionality.
Recommendations:
For versions 11.4 through 12.0, consider disabling the Web UI functionality until a patch is available to prevent potential exploitation. Restrict access to the Web UI to minimize the risk of credentials disclosure within a trusted session.
Fix
XSS
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Security Guardium