CVE-2020-4910: XSS
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191274.
Other sources
IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Cloud Pak System vulnerability?
The vulnerability ID for this IBM Cloud Pak System vulnerability is CVE-2020-4910.
What is the severity of CVE-2020-4910?
The severity of CVE-2020-4910 is medium with a CVSS score of 4.8.
How does CVE-2020-4910 affect IBM Cloud Pak System?
CVE-2020-4910 allows users to embed arbitrary JavaScript code in the Web UI of IBM Cloud Pak System, potentially leading to credentials disclosure within a trusted session.
Which versions of IBM Cloud Pak System are affected by CVE-2020-4910?
IBM Cloud Pak System versions 2.3.0.0 to 2.3.3.3 are affected by CVE-2020-4910.
Is there a fix for CVE-2020-4910?
Yes, IBM has released a fix for CVE-2020-4910. Refer to the IBM support page for more information.