IBM Application Gateway
cpe:2.3:a:ibm:application_gateway:*:*:*:*:*:*:*
- >= 23.10, <= 25.09
A vulnerability allowing HTML injection has been identified in IBM Application Gateway versions 23.10 through 25.09. This issue enables remote attackers to inject malicious HTML code, which would be executed in the context of the victim's web browser, potentially leading to unauthorized actions on the hosting site.
Exploitation of this vulnerability allows for HTML injection, where injected code is executed in the context of the user's browser, potentially leading to cross-site scripting (XSS) scenarios.
Users are encouraged to update to the latest version of IBM Application Gateway. For those using the container version, the latest version can be obtained by pulling from the IBM Container Registry. Instructions for this are available in the IBM Application Gateway documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.