Lucene search

K
ibmIBMF5F0C3149F7A36CDE1F7DC845FBE96ABC6CBBABF87FBB8F491B35354F0FE2F5A
HistoryAug 11, 2020 - 7:18 p.m.

Security Bulletin: A vulnerability in jQuery affects IBM WIoTP MessageGateway (CVE-2020-7656)

2020-08-1119:18:51
www.ibm.com
25

0.002 Low

EPSS

Percentile

51.9%

Summary

There is a vulnerability in jQuery that affects IBM WIoTP MessageGateway.

Vulnerability Details

CVEID:CVE-2020-7656
**DESCRIPTION:**jQuery is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the load method. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base score: 6.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/182264 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM WIoTP MessageGateway 5.0.0.1
IBM IoT MessageSight 5.0.0.0
IBM IoT MessageSight 2.0

Remediation/Fixes

Product

| VRMF| APAR| Remediation/First Fix
—|—|—|—
IBM WIoTP MessageGateway|

5.0.0.2

|

IT33689

| 5.0.0.2-IBM-IMA-IFIT33689
IBM MessageSight|

5.0.0.0

|

IT33689

| 5.0.0.0-IBM-IMA-IFIT33689
IBM MessageSight|

2.0.0.2

|

IT33689

| 2.0.0.2-IBM-IMA-IFIT33689

Workarounds and Mitigations

None