CVE-2023-24966

All FrameworksWebSphereCWE-79CVE-2023-24966

CVE-2023-24966

State: PUBLISHED · Published: 2023-04-27 · Updated: 2025-01-30 · Assigner: ibm
Description
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246904.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/24xxx/CVE-2023-24966.json