Lucene search

K
ibmIBM2258E9F3B1A38F7C9DD7A4F8512E3C470E4A0D53A6A2080EF8CBC65088752C57
HistoryJul 23, 2021 - 3:28 p.m.

Security Bulletin: i2 Analyse and Analyst's Notebook Premium have hyperlink clicking vulnerability (CVE-2021-29770)

2021-07-2315:28:02
www.ibm.com
4
ibm
analyze
analyst's notebook
cve-2021-29770
vulnerability
hyperlink

EPSS

0.001

Percentile

19.6%

Summary

IBM i2 Analyse and Analyst’s Notebook Premium are vulnerable to malicious hyperlinks in certain data fields

Vulnerability Details

CVEID:CVE-2021-29770
**DESCRIPTION:**IBM i2 Analyst's Notebook Premium could allow an authenticated user to perform unauthorized actions due to hazardous input validation.
CVSS Base score: 4.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/202771 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM i2 Analyze IBM i2 Analyze 4.3.1
IBM i2 Analyze IBM i2 Analyze 4.3.0
IBM i2 Analyze IBM i2 Analyze 4.3.2

Remediation/Fixes

Please visit you IBM customer portal to pick up the Analyst’s Notebook Premium 9.2.4 continuous delivery update

Workarounds and Mitigations

None

EPSS

0.001

Percentile

19.6%

Related for 2258E9F3B1A38F7C9DD7A4F8512E3C470E4A0D53A6A2080EF8CBC65088752C57