Description
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected products
- IBM Corporation / Kenexa LCMS Premier on Cloud9.0 – 9.0
- IBM Corporation / Kenexa LCMS Premier on Cloud9.1 – 9.1
- IBM Corporation / Kenexa LCMS Premier on Cloud9.2 – 9.2
- IBM Corporation / Kenexa LCMS Premier on Cloud9.2.1 – 9.2.1
- IBM Corporation / Kenexa LCMS Premier on Cloud9.3.0 – 9.3.0
- IBM Corporation / Kenexa LCMS Premier on Cloud9.4.0 – 9.4.0
- IBM Corporation / Kenexa LCMS Premier on Cloud9.5.0 – 9.5.0
- IBM Corporation / Kenexa LCMS Premier on Cloud10.0.0 – 10.0.0
- IBM Corporation / Kenexa LCMS Premier on Cloud10.1.0 – 10.1.0
- IBM Corporation / Kenexa LCMS Premier on Cloud10.2.0 – 10.2.0