A reflected cross-site scripting (XSS) vulnerability was found in Application Performance Management. Cross-Site Scripting (XSS) attacks occur when data enters a Web application through an untrusted source, most frequently a web request and the data is included in dynamic content that is sent to a web user without being validated for malicious content. The malicious content sent to the web browser often takes the form of a segment of JavaScript, but may also include HTML, Flash, or any other type of code that the browser may execute. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim’s session token or login credentials or performing arbitrary actions on the victim’s behalf
CVE(s): Not Applicable
Affected product(s) and affected version(s):
IBM Monitoring 8.1.3
IBM Application Diagnostics 8.1.3
IBM Application Performance Management 8.1.3
IBM Application Performance Management Advanced 8.1.3
IBM Cloud Application Performance Management, Base Private 8.1.4
IBM Cloud Application Performance Management, Advanced Private 8.1.4
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10879073
X-Force Database:
The post IBM Security Bulletin: A reflected cross-site scripting (XSS) vulnerability affects IBM Performance Management products appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ibm.co/2I7yLC2
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.