Lucene search

K
ibmIBM7E9689C021B5E152C5EDE1E95FFAD6A78878353F091B2618897D5E5F37B5095E
HistoryAug 12, 2024 - 4:25 a.m.

Security Bulletin: IBM Common Licensing is vulnerable to stored cross-site scripting in IBM LKS Administration Reporting Tool and its Agent.

2024-08-1204:25:19
www.ibm.com
3
ibm common licensing
stored cross-site scripting
version 9.0.0.1
remediation
interim fix pack
web ui
credentials disclosure

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

13.8%

Summary

IBM LKS Administration Reporting Tool and its Agent are vulnerable to stored cross-site scripting. This has been addressed in the remediation section

Vulnerability Details

CVEID:CVE-2024-41774
**DESCRIPTION:**IBM Common Licensing is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/350348 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Common Licensing Agent 9.0
IBM Common Licensing ART 9.0

Remediation/Fixes

Download and apply Interim Fix Pack IBM_Common_Licensing_ICL_9.0.0.1 from Fix Central

Users are strongly advised to update to the latest version (IBM Common Licensing 9.0.0.1) to mitigate any potential risks associated with this vulnerability.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcommon_licensingMatch9.0
VendorProductVersionCPE
ibmcommon_licensing9.0cpe:2.3:a:ibm:common_licensing:9.0:*:*:*:*:*:*:*

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

13.8%

Related for 7E9689C021B5E152C5EDE1E95FFAD6A78878353F091B2618897D5E5F37B5095E