First published: Mon Sep 30 2019(Updated: )
IBM WebSphere Extreme Scale Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere eXtreme Scale | >=8.6.0<8.6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4115 is classified as medium, due to its potential for cross-site scripting attacks.
To fix CVE-2019-4115, upgrade to IBM WebSphere eXtreme Scale version 8.6.1.3 or later.
CVE-2019-4115 is a cross-site scripting (XSS) vulnerability affecting the IBM WebSphere Extreme Scale Admin API.
The potential impacts of CVE-2019-4115 include unauthorized access and credentials disclosure within a trusted session.
IBM WebSphere eXtreme Scale versions between 8.6.0 and 8.6.1.3 are affected by CVE-2019-4115.