Lucene search

K
ibmIBMCCACCFC1AA7609A1DB2901B5064835990A01B9C6D1D66E37251A15461F0FFB33
HistoryJan 28, 2021 - 7:16 p.m.

Security Bulletin: Daeja ViewONE Virtual is affected by a Cross-Site Scripting vulnerability

2021-01-2819:16:14
www.ibm.com
7
ibm
daeja viewone virtual
cross-site scripting
vulnerability
versions

EPSS

0.001

Percentile

25.3%

Summary

IBM Daeja ViewONE Virtual is vulnerable to Persistent Cross-site Scripting attack

Vulnerability Details

CVEID: CVE-2018-1399**
DESCRIPTION:** IBM Daeja ViewONE Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base Score: 5.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/138435 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

IBM Daeja ViewONE Virtual 4.1.5, IBM Deaja ViewONE Virtual 5.0.1, 5.0.2 and 5.0.3

Remediation/Fixes

Apply IBM Daeja ViewONE 5.0.3 IFix003 to version 5.0.1, 5.0.2 and 5.0.3 installations.

Apply IBM Daeja ViewONE 4.1.5.2 IFix001 to version 4.1.5.2 installations.

Apply IBM Daeja ViewONE 4.1.5.1 IFix027 to version 4.1.5.1 installations.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

25.3%

Related for CCACCFC1AA7609A1DB2901B5064835990A01B9C6D1D66E37251A15461F0FFB33