Medium severity5.4NVD Advisory· Published Nov 1, 2017· Updated May 13, 2026
CVE-2017-1552
CVE-2017-1552
Description
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 131396.
Affected products
3- IBM/BigInsightsv5Range: 4.2.0
cpe:2.3:a:ibm:infosphere_biginsights:4.2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:infosphere_biginsights:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_biginsights:4.2.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/docview.wssnvdPatchVendor Advisory
- www.securityfocus.com/bid/101588nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/131396nvdVDB Entry
News mentions
0No linked articles in our index yet.