|Date: (C)2017-11-02 (M)2017-11-17|
|CVSS Score: 4.9||Access Vector: NETWORK|
|Exploitability Subscore: 6.8||Access Complexity: MEDIUM|
|Impact Subscore: 4.9||Authentication: SINGLE_INSTANCE|
| ||Confidentiality: PARTIAL|
| ||Integrity: PARTIAL|
| ||Availability: NONE|
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 131396.