CVE-2019-4608: XSS
IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168508.
Other sources
IBM Tivoli Workload Scheduler is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4608?
CVE-2019-4608 is classified as a medium severity vulnerability due to the potential for credentials disclosure via cross-site scripting in IBM Tivoli Workload Scheduler 9.3.
How do I fix CVE-2019-4608?
To mitigate CVE-2019-4608, upgrade to a patched version of IBM Tivoli Workload Scheduler beyond 9.3 to eliminate cross-site scripting risks.
What impact does CVE-2019-4608 have on users?
CVE-2019-4608 can allow attackers to execute arbitrary JavaScript code in the web UI, potentially leading to unauthorized access to user credentials.
Who is affected by CVE-2019-4608?
Users of IBM Tivoli Workload Scheduler version 9.3 are directly affected by CVE-2019-4608.
When was CVE-2019-4608 disclosed?
CVE-2019-4608 was disclosed in 2019 and relates to a security vulnerability identified in IBM Tivoli Workload Scheduler.