CVE-2024-28761

Severity
5.4MEDIUM
EPSS
0.2%
top 61.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 14

Description

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDibm/app_connect_enterprise11.0.0.111.0.0.26+1
CVEListV5ibm/app_connect_enterprise11.0.0.111.0.0.25+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rrxx-mf3x-75gw: IBM App Connect Enterprise 112024-05-14
CVEList
IBM App Connect Enterprise HTML injection2024-05-11
CVE-2024-28761 (MEDIUM CVSS 5.4) | IBM App Connect Enterprise 11.0.0.1 | cvebase.io