Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-05120
HistoryJul 14, 2021 - 12:00 a.m.

IBM Cloud Pak for Applications Cross-Site Scripting Vulnerability (CNVD-2022-05120)

2021-07-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
ibm cloud pak
cross-site scripting
automation platform
cloud security
vulnerability
usa
ibm

EPSS

0.001

Percentile

19.6%

IBM Cloud Pak for Automation is an intelligent software platform used to build automation applications in cloud environments from IBM USA. The platform uses pre-integrated automation technologies and low-code tools to design, build, and run automation applications and services on any cloud.A cross-site scripting vulnerability exists in IBM Cloud Pak for Applications, which stems from the fact that Cloud Pak for Applications allows users to embed arbitrary JavaScript code to change the intended functionality. An attacker could exploit the vulnerability to cause exposure of credentials in a trusted session.

EPSS

0.001

Percentile

19.6%

Related for CNVD-2022-05120