Lucene search

K
ibmIBMDC4E8084CA0D1C38A3D593E53ABB4406A8CEFBA224FCBA8D04903911BDD41103
HistoryApr 08, 2021 - 8:59 p.m.

Security Bulletin: A Security vulnerability in the IBM Dojo Toolkit affects InfoSphere Big Insights (CVE-2014-8917)

2021-04-0820:59:42
www.ibm.com
5

EPSS

0.004

Percentile

73.4%

Summary

IBM Dojo Toolkit is a component that is used by InfoSphere BigInsights. The IBM Dojo Toolkit that is shipped with InfoSphere BigInsights includes resource files that contain cross-site scripting vulnerability.

Vulnerability Details

CVEID: CVE-2014-8917** **
DESCRIPTION: IBM Dojo Toolkit is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victimโ€™s Web browser within the security context of the hosting Web site, after the URL is clicked. An attacker could use this vulnerability to steal the victimโ€™s cookie-based authentication credentials

CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99303 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

InfoSphere BigInsights 1.0 through 3.0.0.1

Remediation/Fixes

The recommended solution is to apply the appropriate fix for this vulnerability. For all the affected versions apply the interim fix available from Fix Central.

EPSS

0.004

Percentile

73.4%

Related for DC4E8084CA0D1C38A3D593E53ABB4406A8CEFBA224FCBA8D04903911BDD41103