First published: Tue Sep 21 2021(Updated: )
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204334.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | =1.1.3.10 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
IBM Jazz for Service Management | <=1.1.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2021-29814.
IBM Jazz for Service Management version 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI are affected by this vulnerability.
CVE-2021-29814 has a severity of 6.4, which is considered as medium.
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
You can find more information about this vulnerability at the following references: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/204334) and [IBM Support](https://www.ibm.com/support/pages/node/6491539).