First published: Mon Dec 17 2018(Updated: )
IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152080.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | >=10.0<=10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1889 is classified as medium due to its potential for JavaScript injection and credential disclosure.
To fix CVE-2018-1889, upgrade IBM Security Guardium to version 10.6 or later, which contains the necessary patches to mitigate the vulnerability.
IBM Security Guardium versions 10.0 and 10.5 are affected by CVE-2018-1889.
CVE-2018-1889 enables cross-site scripting attacks that can lead to malicious JavaScript execution and possibly credential disclosure.
CVE-2018-1889 is primarily a client-side vulnerability that affects the Web UI of IBM Security Guardium.