Lucene search

K
ibmIBM2138F968F6D5BD2267B9BFDB832E842FCE7A443F8DA9871DEBD60C36F96BB3C6
HistoryNov 10, 2020 - 10:47 p.m.

Security Bulletin: IBM WebSphere Application Server Network Deployment security vulnerabilities in IBM Content Foundation on Cloud

2020-11-1022:47:27
www.ibm.com
16
ibm content foundation
cloud
websphere application server
security vulnerabilities
cross-site scripting
credentials disclosure

EPSS

0.001

Percentile

29.7%

Summary

IBM Content Foundation on Cloud in IBM WebSphere Application Server Network Deployment has security vulnerablities.

Vulnerability Details

CVEID:CVE-2020-4304
**DESCRIPTION:**IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176670.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176670 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

CVEID:CVE-2020-4303
**DESCRIPTION:**IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176668.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/176668 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Content Foundation on Cloud 5.5.3
5.5.4

Remediation/Fixes

WebSphere security vulnerabilities

Install WebSphere fix, or one of the below releases to resolve the security vulnerabilities.

Product ** VRMF** ** APAR** Remediation/First Fix
IBM Content Foundation on Cloud 5.5.3
5.5.4 PJ46141
PJ46141 5.5.3.0-P8CPE-Container-IF003 - July 16, 2020
5.5.4.0-P8CPE-Container-IF002 - July 21, 2020

Only versions covered by continuous support for fixes are listed. Please apply the listed update to remediate.

Workarounds and Mitigations

Install WebSphere patch PH22080 or Liberty Fix Pack 20.0.0.4 or higher, or upgrade to a release where this is fixed.

EPSS

0.001

Percentile

29.7%

Related for 2138F968F6D5BD2267B9BFDB832E842FCE7A443F8DA9871DEBD60C36F96BB3C6