CVE-2019-4450: XSS
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.
Other sources
IBM Navigator for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4450?
CVE-2019-4450 is classified as a medium severity vulnerability due to its potential for credential disclosure through cross-site scripting.
How do I fix CVE-2019-4450?
To fix CVE-2019-4450, IBM recommends applying the latest security patches provided for IBM i versions 7.2, 7.3, and 7.4.
What are the affected versions in CVE-2019-4450?
The affected versions for CVE-2019-4450 are IBM i 7.2, 7.3, and 7.4.
What type of vulnerability is CVE-2019-4450?
CVE-2019-4450 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary JavaScript code.
Can CVE-2019-4450 lead to serious consequences?
Yes, CVE-2019-4450 can lead to serious consequences such as credentials disclosure within a trusted session.