First published: Tue Sep 21 2021(Updated: )
IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208405.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | =1.1.3.10 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
<=1.1.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38877 is medium with a CVSS score of 6.4.
CVE-2021-38877 allows users to embed arbitrary JavaScript code in the Web UI of IBM Jazz for Service Management, potentially leading to credentials disclosure.
Yes, IBM Jazz for Service Management version 1.1.3.10 is vulnerable to CVE-2021-38877.
To fix CVE-2021-38877, it is recommended to upgrade to a patched version or apply the necessary security updates provided by IBM.
The CWE of CVE-2021-38877 is CWE-79 (Cross-Site Scripting).