CVE-2022-36776: XSS
IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233663.
Other sources
IBM Cloud Pak for Security (CP4S) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-36776.
What software is affected by this vulnerability?
IBM Cloud Pak for Security (CP4S) versions 1.10.0.0 and 1.10.2.0 are affected.
What is the severity of CVE-2022-36776?
The severity of CVE-2022-36776 is medium with a severity value of 5.4.
What is the impact of this vulnerability?
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
Are there any known fixes for this vulnerability?
Yes, IBM has provided fixes for this vulnerability. Please refer to the IBM support page for more information.