Lucene search

K
ibmIBM1BC1BBD2406B2A6EF54915D3A9F7303447F1E9A74BFAA21C16496E625A76B261
HistoryOct 28, 2020 - 6:18 p.m.

Security Bulletin: Vulnerability identified in Apache ActiveMQ used in Cloud Pak System (CVE-2020-1941)

2020-10-2818:18:48
www.ibm.com
7

0.003 Low

EPSS

Percentile

70.9%

Summary

Cross Site scripting vulnerability has been identified in the admin GUI of Apache ActiveMQ in IBM Cloud Pak System Software. Cloud Pak System addressed vulnerability and package removed.

Vulnerability Details

CVEID:CVE-2020-1941
**DESCRIPTION:**Apache ActiveMQ is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the admin GUI. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/181957 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak System 2.2.6, 2.3, 2.3.0.1

Remediation/Fixes

For unsupported releases or end of support releases recommendation is to upgrade to supported release of the product.

For V2.3, V2.3.0.1,

Upgrade to V2.3.1.1 or later of the product.

Information on upgrading can be found here: http://www.ibm.com/support/docview.wss?uid=ibm10887959.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm cloud pak systemeq2.3

0.003 Low

EPSS

Percentile

70.9%

Related for 1BC1BBD2406B2A6EF54915D3A9F7303447F1E9A74BFAA21C16496E625A76B261