CVE-2020-4679: XSS
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186424.
Other sources
IBM Security Guardium is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4679?
The severity of CVE-2020-4679 is categorized as medium due to its potential for cross-site scripting attacks.
How do I fix CVE-2020-4679?
To fix CVE-2020-4679, upgrade IBM Security Guardium to the latest version that addresses this vulnerability.
What are the affected versions for CVE-2020-4679?
CVE-2020-4679 affects IBM Security Guardium versions up to and including 11.2.
What impact can CVE-2020-4679 have on users?
CVE-2020-4679 can allow attackers to execute arbitrary JavaScript in the Web UI, potentially leading to credential disclosure.
Is CVE-2020-4679 a cross-site scripting vulnerability?
Yes, CVE-2020-4679 is specifically identified as a cross-site scripting vulnerability affecting IBM Security Guardium.