Lucene search

K
ibmIBM6260B1D4A6AAD29E3DCCC4C33DC348DFC2675905584FF9150D05A0D1D5685D33
HistoryApr 27, 2022 - 10:23 a.m.

Security Bulletin: Security vulnerabilities have been identified in IBM WebSphere Application Server used by IBM InfoSphere Master Data Management 11.6

2022-04-2710:23:01
www.ibm.com
10
cross-site scripting
ibm websphere
infosphere master data management

EPSS

0.001

Percentile

29.7%

Summary

IBM WebSphere Application Server ND 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.

Vulnerability Details

CVEID:CVE-2020-4575
**DESCRIPTION:**IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
CVSS Base score: 4.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/184363 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
InfoSphere Master Data Management 11.6

Remediation/Fixes

Principal Product and Version(s) Affected Supporting Product and Version Affected Supporting Product Security Bulletin
IBM InfoSphere Master Data Management 11.6
IBM WebSphere Application Server versions 9.0.

Security Bulletin: WebSphere Application Server ND is vulnerable to cross-site scripting (CVE-2020-4575)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibminfosphere_master_data_managementMatch11.6
VendorProductVersionCPE
ibminfosphere_master_data_management11.6cpe:2.3:a:ibm:infosphere_master_data_management:11.6:*:*:*:*:*:*:*

EPSS

0.001

Percentile

29.7%

Related for 6260B1D4A6AAD29E3DCCC4C33DC348DFC2675905584FF9150D05A0D1D5685D33