First published: Wed Apr 28 2021(Updated: )
IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199281.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Security | =1.5.0.0 | |
IBM Cloud Pak for Security | =1.5.0.1 | |
<=1.5.0.0 | ||
<=1.5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for IBM Cloud Pak for Security (CP4S) is CVE-2021-20577.
The severity of CVE-2021-20577 is medium.
The cross-site scripting vulnerability in IBM Cloud Pak for Security (CP4S) allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
An attacker can exploit CVE-2021-20577 by injecting arbitrary JavaScript code into the Web UI, which can alter the intended functionality and potentially disclose credentials within a trusted session.
Yes, IBM has provided a fix for the cross-site scripting vulnerability in IBM Cloud Pak for Security (CP4S). It is recommended to update to the latest version of the software.