IBM InfoSphere Master Data Management CVE-2015-7423 Unspecified Cross Site Scripting Vulnerability
BID:103687
CVE-2015-7423 |Info
IBM InfoSphere Master Data Management CVE-2015-7423 Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 103687 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-7423 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2018 12:00AM |
| Updated: | Apr 04 2018 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM InfoSphere Master Data Management Collaborative Edition 9.1 IBM InfoSphere Master Data Management Collaborative Edition 11.4 IBM InfoSphere Master Data Management Collaborative Edition 11.3 IBM InfoSphere Master Data Management Collaborative Edition 11.0 IBM InfoSphere Master Data Management Collaborative Edition 10.1 |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Master Data Management CVE-2015-7423 Unspecified Cross Site Scripting Vulnerability
IBM InfoSphere Master Data Management is prone to an unspecified cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
IBM InfoSphere Master Data Management 11.4, 11.3, 11.0, 10.1, and 9.1 are vulnerable.
IBM InfoSphere Master Data Management is prone to an unspecified cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
IBM InfoSphere Master Data Management 11.4, 11.3, 11.0, 10.1, and 9.1 are vulnerable.