Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05115
HistoryJul 14, 2021 - 12:00 a.m.

IBM Cloud Pak for Applications Cross-Site Scripting Vulnerability (CNVD-2022-05115)

2021-07-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
ibm cloud pak
cross-site scripting
vulnerability
cloud-native development
javascript code
web ui
credentials
trusted session

EPSS

0.001

Percentile

19.6%

IBM Cloud Pak for Applications is an application from IBM of America, Inc. providing cloud-native development solutions that deliver rapid value. IBM Cloud Pak for Applications has a cross-site scripting vulnerability that stems from the application’s IBM Cloud Pak being vulnerable to cross-site scripting attacks. An attacker could exploit the vulnerability to allow a user to embed arbitrary JavaScript code in the Web UI to change the intended functionality, which could result in exposing credentials in a trusted session.

EPSS

0.001

Percentile

19.6%

Related for CNVD-2022-05115