CVE-2023-47699: IBM Secure Proxy cross-site scripting
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270974.
Other sources
IBM Sterling Secure Proxy is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47699?
CVE-2023-47699 is classified as a cross-site scripting vulnerability that can lead to credentials disclosure.
How do I fix CVE-2023-47699?
To fix CVE-2023-47699, apply the latest security patches provided by IBM for versions 6.0.3 and 6.1.0 of Sterling Secure Proxy.
What are the affected versions of CVE-2023-47699?
CVE-2023-47699 affects IBM Sterling Secure Proxy versions 6.0.3 and 6.1.0.
What potential risks does CVE-2023-47699 pose?
CVE-2023-47699 can allow attackers to execute arbitrary JavaScript code in the Web UI, compromising user sessions and potentially exposing sensitive data.
Who is affected by CVE-2023-47699?
Organizations using IBM Sterling Secure Proxy versions 6.0.3 and 6.1.0 are at risk due to CVE-2023-47699.