CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-39735

Medium Severity
Ibm
SVRS
30/100

CVSSv3
5.4/10

EPSS
0.00093/1

CVE-2024-39735: Cross-site scripting vulnerability in IBM Datacap Navigator. This security flaw allows authenticated users to inject arbitrary JavaScript code into the Web UI. This can compromise functionality and potentially lead to credential disclosure.

IBM Datacap Navigator versions 9.1.5 through 9.1.9 are affected by this CWE-79 vulnerability. Although the CVSS score is 5.4, indicating a medium severity, organizations should assess their specific risk. With an SVRS score of 30, the immediate risk is relatively low but should be monitored. Exploitation can occur within a trusted session if not addressed promptly. Mitigate this risk by applying available patches or workarounds from IBM to prevent unauthorized script execution.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:L
UI:R
S:C
C:L
I:L
A:N
2024-07-15

2024-07-16

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-39735 | IBM Datacap Navigator 9.1.5/9.1.6/9.1.7/9.1.8/9.1.9 Web UI cross site scripting (XFDB-296002)
vuldb.com2025-03-18
CVE-2024-39735 | IBM Datacap Navigator 9.1.5/9.1.6/9.1.7/9.1.8/9.1.9 Web UI cross site scripting (XFDB-296002) | A vulnerability classified as problematic has been found in IBM Datacap Navigator 9.1.5/9.1.6/9.1.7/9.1.8/9.1.9. This affects an unknown part of the component Web UI. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-39735. It is possible to initiate the attack remotely. There
vuldb.com
rss
forum
news

Social Media

CVE-2024-39735 IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary … https://t.co/ccFN5Ab0bE
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppIbmdatacap
AppIbmdatacap_navigator

References

ReferenceLink
[email protected]https://exchange.xforce.ibmcloud.com/vulnerabilities/296002
[email protected]https://www.ibm.com/support/pages/node/7160185

CWE Details

CWE IDCWE NameDescription
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence