Lucene search

HistoryOct 07, 2020 - 9:18 p.m.

Security Bulletin: Steps to update DataQuant Workstation and DataQuant WebSphere plugins.


0.002 Low





Query is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the load method. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Vulnerability Details

**DESCRIPTION:**jQuery is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the load method. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base score: 6.1
CVSS Temporal Score: See: for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
DataQuant for z/OS 2.1
DataQuant for Multiplatforms 2.1


Please see “Workarounds.”

Workarounds and Mitigations

Steps for DataQuant Workstation:

  1. Close DataQuant.
  2. Navigate to the plugins directory present within DataQuant install directory.

Example: <DATAQUANT_HOME>/DataQuant For Workstation/plugins

  1. Locate the folder - in the above Directory. Take a backup & remove the directory along with contents from this location.
  2. Download the attached zip file & extract it to a temporary location.
  3. Place the extracted folder in the directory <DATAQUANT_HOME>/DataQuant For Workstation/plugins.
  4. Once replaced, launch DataQuant.

Steps for DataQuant WebSphere:

  1. On a deployed product instance, stop the DataQuant WebSphere application.
  2. Locate the plugin folder - Take a backup and remove it from the plugins directory.

Standard location → <IBM_WebSphere>\AppServer\profiles\AppSrv01\installedApps\ams-vm-qmf11Node01Cell\DataQuant for WebSphere 2.1.ear\DataQuantWebSphere21.war\WEB-INF\eclipse\plugins\

  1. Download the attached zip file & extract it to a temporary location.
  2. Place the extracted folder in the directory → <IBM_WebSphere>\AppServer\profiles\AppSrv01\installedApps\MyMachineNode01Cell\DataQuant for WebSphere 2.1.ear\DataQuantWebSphere21.war\WEB-INF\eclipse\plugins\
  3. Optionally, to copy files for WebSphere application server on windows using XCOPY command run step 6
  4. Open command prompt with ‘Run As Administrator’ option and use the XCOPY command

For Example → Xcopy /E /I “<UserLocationForDownloadedZip>[](<;).reporter_2.1.8.20200927” “<IBM_WebSphere>\AppServer\profiles\AppSrv01\installedApps\MyMachineNode01Cell\DataQuant for WebSphere 2.1.ear\DataQuantWebSphere21.war\WEB-INF\eclipse\plugins[](<;).reporter_2.1.8.20200927”

  1. Start the DataQuant application within WebSphere.

ibm dataquant for z/oseq2.1