First published: Mon Oct 18 2021(Updated: )
IBM Cloud Pak - Risk Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Risk Manager on CP4S | <=CP4S 1.7.0.0 | |
IBM Security Risk Manager on CP4S | =1.7.0.0 | |
Red Hat OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29912 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To remediate CVE-2021-29912, ensure you update to a patched version of IBM Security Risk Manager beyond CP4S 1.7.0.0.
CVE-2021-29912 affects IBM Security Risk Manager on CP4S version 1.7.0.0 and earlier.
CVE-2021-29912 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary JavaScript code.
CVE-2021-29912 could lead to credential disclosure and manipulation of the intended functionality within a trusted session.