Security Advisory

CVE-2021-20577

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-05-10 16:20:17
Last updated 2024-09-17 00:16:35
Assigner ibm
CVSS score 4.3
State PUBLISHED

Description

IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199281.