First published: Tue Apr 20 2021(Updated: )
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199400.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | >=5.0.0<=5.0.5.6 | |
IBM Spectrum Scale | >=5.1.0<=5.1.0.2 | |
Linux Linux kernel | ||
<=5.0.0 - 5.0.5.6 | ||
<=5.1.0 - 5.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-29666.
The severity of CVE-2021-29666 is medium with a CVSS score of 5.4.
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI of IBM Spectrum Scale, potentially leading to credentials disclosure within a trusted session.
IBM Spectrum Scale versions 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 are affected by CVE-2021-29666.
To fix the CVE-2021-29666 vulnerability, it is recommended to apply the latest patches and updates provided by IBM.