A vulnerability has been identified in IBM Cloud Pak for Applications v4.3 which may expose a cross-site scripting attack.
CVEID:CVE-2021-20363
**DESCRIPTION:**IBM Cloud Pak for Applications is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195034 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Cloud Pak for Applications | All |
IBM Cloud Pak for Applications 4.3.1 is updated to not allow users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
None