Description
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998294.
Affected products
- IBM Corporation / Connections4.5 – 4.5
- IBM Corporation / Connections3.0 – 3.0
- IBM Corporation / Connections3.0.1 – 3.0.1
- IBM Corporation / Connections3.0.1.1 – 3.0.1.1
- IBM Corporation / Connections4.0 – 4.0
- IBM Corporation / Connections5.0 – 5.0
- IBM Corporation / Connections5.5 – 5.5