Lucene search

K
ibmIBM263C5D7B9C563798EF6F16FB48B508474CF7C5D6DC733506446F9C3E6FC9103A
HistoryJun 01, 2021 - 4:16 p.m.

Security Bulletin: Embedded WebSphere Application Server is affected by vulnerability in Dojo, which affects Content Collector for Email

2021-06-0116:16:42
www.ibm.com
17
websphere application server
dojo
content collector

EPSS

0.002

Percentile

61.9%

Summary

Embedded WebSphere Application Server is affected by vulnerability in Dojo affects Content Collector for Email.

Vulnerability Details

CVEID:CVE-2020-5258
**DESCRIPTION:**Dojo dojo could allow a remote attacker to inject arbitrary code on the system, caused by a prototype pollution flaw. By injecting other values, an attacker could exploit this vulnerability to overwrite, or pollute, a JavaScript application object prototype of the base object.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/177751 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Content Collector for Email 4.0.x

Remediation/Fixes

Product VRM Remediation
Content Collector for Email 4.0.1 Use Content Collector for Email 4.0.1.9 Interim Fix IF010
Content Collector for Email 4.0.1
Use Content Collector for Email 4.0.1.12 Interim Fix IF001

Workarounds and Mitigations

None

EPSS

0.002

Percentile

61.9%