Vulnerabilities
Vulnerable Software
Ibm:  >> I  >> 7.4  Security Vulnerabilities
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-11-09
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the restored system. IBM X-Force ID: 165592.
CVSS Score
6.7
EPSS Score
0.0
Published
2019-08-29


Contact Us

Shodan ® - All rights reserved