First published: Fri Jul 24 2020(Updated: )
IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Intelligent Operations Center | =5.1.0 | |
IBM Intelligent Operations Center | =5.1.0.2 | |
IBM Intelligent Operations Center | =5.1.0.3 | |
IBM Intelligent Operations Center | =5.1.0.4 | |
IBM Intelligent Operations Center | =5.1.0.6 | |
IBM Intelligent Operations Center | =5.2 | |
IBM Intelligent Operations Center | =5.2.1 | |
IBM Intelligent Operations Center for Emergency Management | =5.1.0 | |
IBM Intelligent Operations Center for Emergency Management | =5.1.0.2 | |
IBM Intelligent Operations Center for Emergency Management | =5.1.0.3 | |
IBM Intelligent Operations Center for Emergency Management | =5.1.0.4 | |
IBM Intelligent Operations Center for Emergency Management | =5.1.0.6 | |
IBM Water Operations for Waternamics | =5.1.0 | |
IBM Water Operations for Waternamics | =5.1.0.3 | |
IBM Water Operations for Waternamics | =5.1.0.4 | |
IBM Water Operations for Waternamics | =5.1.0.6 | |
IBM Water Operations for Waternamics | =5.2 | |
IBM Water Operations for Waternamics | =5.2.1 | |
<=5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6, 5.2, 5.2. | ||
<=5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6, 5.2, 5.2.1 | ||
<=5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM Intelligent Operations Center for Emergency Management (Linux) vulnerability is CVE-2020-4317.
CVE-2020-4317 has a severity level of medium (5.4).
The affected software versions for CVE-2020-4317 are IBM Intelligent Operations Center (IOC) 5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6, 5.2, 5.2.1, IBM Water Operations for Waternamics (Linux) 5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6, 5.2, 5.2.1, and IBM Intelligent Operations Center for Emergency Management (Linux) 5.1.0, 5.1.0.2, 5.1.0.3, 5.1.0.4, 5.1.0.6.
This vulnerability allows attackers to embed arbitrary JavaScript code in the Web UI, thereby altering its intended functionality.
You can find more information about CVE-2020-4317 at the following references: [link1] [link2].