Intrusion Prevention

IBM.Infosphere.BigInsights.Editor.XSS

Description

This indicates an attack attempt against a Cross-Site Scripting vulnerability in IBM Infosphere BigInsights.
The vulnerability is caused by improper validation of user-supplied input. It allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality, potentially leading to credentials disclosure within a trusted session.

Affected Products

IBM BigInsights 4.1, 4.2

Impact

System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://www-01.ibm.com/support/docview.wss?uid=swg21987499

CVE References

CVE-2016-2992