CVE-2023-40684
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Oct 4, 2023
Updated: Oct 6, 2023
CWE ID 79
Summary
CVE-2023-40684 is a newly identified cross-site scripting (XSS) vulnerability affecting IBM Content Navigator versions 3.0.11, 3.0.13, and 3.0.14 when used with IBM Daeja ViewOne Virtual. This issue enables attackers to inject and execute malicious JavaScript code within the Web UI, potentially altering functionality and leading to sensitive information disclosure, including credentials, within a trusted session (IBM X-Force ID: 264019). IBM users are urged to apply the necessary patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- IBM Content Navigator
Affected Vendors
- IBM Corporation