CERT-In Vulnerability Note
CIVN-2019-0193
IBM Cloud Park System Cross Site Scripting Vulnerability
Original Issue Date:December 10, 2019
Severity Rating: MEDIUM
Systems Affected
- IBM Cloud Pak System 2.3.0
- IBM Cloud Pak System 2.3.0.1
Overview
A vulnerability has been reported in IBM Cloud Park system which could allow an attacker inject arbitrary script code into the web site.
Description
This vulnerability exists in IBM Cloud Park system fails to properly sanitize the user supplied input. An attacker could exploit this vulnerability to execute arbitrary Java script code in the browser of an affected system.
Successful exploitation of this vulnerability could allow the attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Solution
Apply appropriate updates as mentioned in:
https://www.symantec.com/security-center/vulnerabilities/writeup/111035
Vendor Information
FortiGuard
https://www.symantec.com/security-center/vulnerabilities/writeup/111035
References
FortiGuard
https://www.symantec.com/security-center/vulnerabilities/writeup/111035
CVE Name
CVE-2019-4098
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|