CVE-2020-4535: XSS
IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182906.
Other sources
IBM OpenPages with Watson is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4535?
CVE-2020-4535 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2020-4535?
To fix CVE-2020-4535, update IBM OpenPages GRC Platform to version 8.1.0.2 or later.
What type of vulnerability is CVE-2020-4535?
CVE-2020-4535 is a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2020-4535?
CVE-2020-4535 affects users of IBM OpenPages GRC Platform versions prior to 8.1.0.2.
What could be the impact of CVE-2020-4535?
The impact of CVE-2020-4535 could lead to credentials disclosure within a trusted session through embedded JavaScript.