IBM i2 Analyse and Analyst’s Notebook Premium are vulnerable to malicious hyperlinks in certain data fields
CVEID:CVE-2021-29770
**DESCRIPTION:**IBM i2 Analyst's Notebook Premium could allow an authenticated user to perform unauthorized actions due to hazardous input validation.
CVSS Base score: 4.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/202771 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM i2 Analyze | IBM i2 Analyze 4.3.1 |
IBM i2 Analyze | IBM i2 Analyze 4.3.0 |
IBM i2 Analyze | IBM i2 Analyze 4.3.2 |
Please visit you IBM customer portal to pick up the Analyst’s Notebook Premium 9.2.4 continuous delivery update
None