First published: Tue Sep 21 2021(Updated: )
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204330.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | =1.1.3.10 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=1.1.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-29812.
The severity level of CVE-2021-29812 is medium (6.4).
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI are affected by CVE-2021-29812.
CVE-2021-29812 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
No, other operating systems such as IBM AIX, Linux kernel, and Microsoft Windows are not vulnerable to CVE-2021-29812.