First published: Thu Oct 24 2019(Updated: )
IBM Cloud Orchestrator is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Orchestrator Enterprise | >=2.4<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.4<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.5<=2.5.0.9 | |
IBM Cloud Orchestrator Enterprise | >=2.5<=2.5.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4459 is categorized as medium due to the potential for credential disclosure.
To fix CVE-2019-4459, you should upgrade IBM Cloud Orchestrator to version 2.4.0.6 or higher, or 2.5.0.10 or higher.
CVE-2019-4459 affects all versions of IBM Cloud Orchestrator from 2.4 to 2.4.0.5 and from 2.5 to 2.5.0.9.
CVE-2019-4459 can facilitate cross-site scripting (XSS) attacks, allowing arbitrary JavaScript to be embedded.
CVE-2019-4459 is primarily a concern within trusted sessions, making it more exploitable in internal environments.