First published: Fri Mar 06 2020(Updated: )
IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168508.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Workload Scheduler | =9.3 | |
<=9.3.x 9.4.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4608 is classified as a medium severity vulnerability due to the potential for credentials disclosure via cross-site scripting in IBM Tivoli Workload Scheduler 9.3.
To mitigate CVE-2019-4608, upgrade to a patched version of IBM Tivoli Workload Scheduler beyond 9.3 to eliminate cross-site scripting risks.
CVE-2019-4608 can allow attackers to execute arbitrary JavaScript code in the web UI, potentially leading to unauthorized access to user credentials.
Users of IBM Tivoli Workload Scheduler version 9.3 are directly affected by CVE-2019-4608.
CVE-2019-4608 was disclosed in 2019 and relates to a security vulnerability identified in IBM Tivoli Workload Scheduler.