Lucene search

K
ibmIBMCA73FB44FB998F8254264686F9AA822F9F94A481619DA33C3C50AFB9ADA7A930
HistoryNov 10, 2021 - 8:16 a.m.

Security Bulletin: IBM Security SiteProtector System is affected by Cross-Site Scripting (CVE-2020-4140)

2021-11-1008:16:16
www.ibm.com
10
ibm security siteprotector
cross-site scripting
vulnerability
javascript
credentials disclosure
express updates

EPSS

0.001

Percentile

19.6%

Summary

IBM Security SiteProtector System has addressed the following vulnerabilities in Core XPU

Vulnerability Details

CVEID:CVE-2020-4140
**DESCRIPTION:**IBM SiteProtector Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174052 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected products(s)
| Version(s)

—|—
IBM Security SiteProtector System| 3.1.1

Remediation/Fixes

Product
| VRMF
| Remediation/First Fix

—|—|—
IBM Siteprotector system
| 3.1.1
| Apply the appropriate eXPress Updates (XPUs) as identified in the SiteProtector Console Agent view:

ServicePack3_1_1_23.xpu

Workarounds and Mitigations

None

EPSS

0.001

Percentile

19.6%

Related for CA73FB44FB998F8254264686F9AA822F9F94A481619DA33C3C50AFB9ADA7A930