First published: Fri Jul 09 2021(Updated: )
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Netcool/OMNIbus_GUI | <=8.1.x | |
Ibm Tivoli Netcool\/omnibus Gui | =8.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-29805.
The severity of CVE-2021-29805 is medium.
The affected software is IBM Tivoli Netcool/OMNIbus_GUI version 8.1.x.
This vulnerability can be exploited by embedding arbitrary JavaScript code in the Web UI of IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI.
Yes, you can find references for CVE-2021-29805 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/204263) and [Reference 2](https://www.ibm.com/support/pages/node/6471067).