Description
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25847 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245. |
References
History
Tue, 07 Jan 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm app Connect Enterprise |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm app Connect Enterprise |
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-03-13T17:33:41.765Z
Reserved: 2024-03-10T12:22:43.137Z
Link: CVE-2024-28761
Updated: 2024-08-02T00:56:58.044Z
Status : Modified
Published: 2024-05-14T15:14:41.123
Modified: 2025-03-13T18:15:38.963
Link: CVE-2024-28761
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD