First published: Mon Apr 26 2021(Updated: )
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 196624.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | =3.0.0 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=3.0CD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20448 is a vulnerability in IBM Content Navigator 3.0CD that allows for cross-site scripting (XSS) attacks, potentially leading to credentials disclosure.
CVE-2021-20448 allows users to inject arbitrary JavaScript code into the Web UI of IBM Content Navigator, which can alter its intended functionality and possibly lead to the disclosure of credentials.
CVE-2021-20448 has a severity rating of 5.4 (medium).
To fix CVE-2021-20448, users should apply the latest security patch provided by IBM and ensure that the Content Navigator version is updated to the patched version.
Yes, you can find more information about CVE-2021-20448 on the IBM X-Force ID page and the IBM support page.