CVE-2019-4451: XSS
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163493.
Other sources
IBM Security Identity Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4451?
The severity of CVE-2019-4451 is medium.
What is the impact of CVE-2019-4451?
CVE-2019-4451 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Which version of IBM Security Identity Manager is affected by CVE-2019-4451?
IBM Security Identity Manager 6.0.0 is affected by CVE-2019-4451.
How can I fix CVE-2019-4451?
To fix CVE-2019-4451, update to a version of IBM Security Identity Manager that is not vulnerable to this issue.
Where can I find more information about CVE-2019-4451?
More information about CVE-2019-4451 can be found at the following links: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/163493), [link2](https://www.ibm.com/support/pages/node/1288720).