First published: Tue Nov 17 2020(Updated: )
IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191390.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak System | >=2.3.0.0<2.3.3.3 | |
<=2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4916 is a vulnerability in IBM Cloud Pak System 2.3 that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
CVE-2020-4916 has a severity rating of medium (5.5).
Cross-site scripting (XSS) is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
CVE-2020-4916 affects IBM Cloud Pak System 2.3 by allowing users to embed arbitrary JavaScript code in the Web UI, potentially altering the intended functionality and leading to credentials disclosure.
To fix the CVE-2020-4916 vulnerability, it is recommended to upgrade to a version of IBM Cloud Pak System that includes a fix for this vulnerability.