Medium
IBM i 7.2, 7.3, and 7.4 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
IBM
Refer to IBM Security Bulletin for patch, upgrade, or suggested workaround information.