IBM Dojo Toolkit is a component that is used by InfoSphere BigInsights. The IBM Dojo Toolkit that is shipped with InfoSphere BigInsights includes resource files that contain cross-site scripting vulnerability.
CVEID: CVE-2014-8917** **
DESCRIPTION: IBM Dojo Toolkit is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victimโs Web browser within the security context of the hosting Web site, after the URL is clicked. An attacker could use this vulnerability to steal the victimโs cookie-based authentication credentials
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99303 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
InfoSphere BigInsights 1.0 through 3.0.0.1
The recommended solution is to apply the appropriate fix for this vulnerability. For all the affected versions apply the interim fix available from Fix Central.