Lucene search

K
ibmIBMD767E4EC34A90296686E054DDBAAF109CD0E31120E9C07668503E2E429F82386
HistoryJan 13, 2021 - 7:42 p.m.

Security Bulletin: IBM API Connect V5 Developer Portal is vulnerable to cross-site scripting (CVE-2020-4838)

2021-01-1319:42:32
www.ibm.com
8

0.001 Low

EPSS

Percentile

19.6%

Summary

IBM API Connect has addressed the following vulnerability

Vulnerability Details

CVEID:CVE-2020-4838
**DESCRIPTION:**IBM API Connect is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 6.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190036 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
API Connect IBM API Connect V5.0.0.0-5.0.8.10

Remediation/Fixes

Affected Product

|

Addressed in VRMF

|

APAR

|

Remediation / First Fix

—|—|—|—

IBM API Connect

V5.0.0.0-5.0.8.10

|

5.0.8.10 iFix (Developer Portal) released on

December 18th, 2020 or later.

| LI81918 | Addressed in IBM API Connect V5.0.8.10 iFix (Developer Portal)

released on December 18, 2020 or later

Developer Portal is impacted.

Follow this link and find the “Portal” package:

http://www.ibm.com/support/fixcentral/swg/quickorder

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

19.6%

Related for D767E4EC34A90296686E054DDBAAF109CD0E31120E9C07668503E2E429F82386