Description
IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Product status
Credits
benjamin.dixon.vaca8k@statefarm.com, benjamin.dixon.vaca8k@statefarm.com, benjamin.dixon.vaca8k@statefarm.com
References
www.ibm.com/support/pages/node/7270422
