First published: Tue Sep 21 2021(Updated: )
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204824.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | <=1.1.3.10 | |
IBM Jazz for Service Management | =1.1.3.10 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-29832.
The severity of CVE-2021-29832 is medium with a severity value of 6.4.
The vulnerability CVE-2021-29832 affects IBM Jazz for Service Management 1.1.3.10.
CVE-2021-29832 can be exploited by embedding arbitrary JavaScript code in the Web UI of IBM Jazz for Service Management, potentially leading to credentials disclosure.
No, IBM AIX and Linux Linux kernel are not vulnerable to CVE-2021-29832.