Lucene search

K
ibmIBM7D67D80D4B93C266A649B84CAFDD0C7C0525E4EF25DE3D86F84615A02E71F9A3
HistoryJun 05, 2019 - 6:20 a.m.

Security Bulletin: IBM MessageSight/MessageGateway is affected by the following jQuery vulnerability

2019-06-0506:20:01
www.ibm.com
29

0.035 Low

EPSS

Percentile

91.6%

Summary

IBM MessageSight/MessageGateway has addressed the following jQuery vulnerability:

CVE-2019-11358: jQuery mishandles jQuery.extend(true, {}, …)

Vulnerability Details

CVEID: CVE-2019-11358 DESCRIPTION: jQuery, as used in Drupal core, is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to execute script in a victim’s Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials…
CVSS Base Score: 6.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159633&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected IBM MessageSight Affected Versions
IBM MessageSight 1.2.0.0 - 1.2.0.3
IBM MessageSight 2.0.0.0 - 2.0.0.2
IBM MessageSight 5.0.0.0
IBM MessageGateway 5.0.0.1

Remediation/Fixes

IBM MessageSight | 1.2.0.3 | [

1.2.0.3-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886203&gt;)
—|—|—
IBM MessageSight | 2.0.0.2 | [

2.0.0.2-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886207&gt;)
IBM MessageSight | 5.0.0.0 | [

5.0.0.0-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886211&gt;)
IBM MessageGateway | 5.0.0.1 | [

5.0.0.1-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886213&gt;)

Workarounds and Mitigations

None