Lucene search

K
ibmIBM9B5B6ADE9E076465EDCB5161893819A29E4D5386CAB1E8115A6A15030F2E7EDA
HistoryMay 10, 2021 - 5:20 p.m.

Security Bulletin: IBM OpenPages with Watson has addressed a cross-site scripting vulnerability (CVE-2020-4535)

2021-05-1017:20:55
www.ibm.com
5
ibm
openpages
watson
cross-site scripting
vulnerability
validation
javascript
credentials disclosure
version v8.1
fix
download url

EPSS

0.001

Percentile

19.6%

Summary

IBM OpenPages with Watson has addressed a cross-site scripting vulnerability caused by improper validation.

Vulnerability Details

CVEID:CVE-2020-4535
**DESCRIPTION:**IBM OpenPages with Watson is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/182906 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

IBM OpenPages with Watson version v8.1

Remediation/Fixes

A fix has been created for each affected version of the named product. Download and install the fix as soon as possible. Fixes and installation instructions are provided at the URL listed below:

Fix Download URL
For IBM OpenPages with Watson 8.1
- Apply 8.1.0.2or later <https://www.ibm.com/support/pages/openpages-watson-81-fix-pack-2&gt;

Workarounds and Mitigations

None

EPSS

0.001

Percentile

19.6%

Related for 9B5B6ADE9E076465EDCB5161893819A29E4D5386CAB1E8115A6A15030F2E7EDA