Wiz Agents & Workflows are here

CVE-2020-14988
Bloomreach Experience Manager vulnerability analysis and mitigation

Overview

CVE-2020-14988 is a cross-site scripting (XSS) vulnerability discovered in Bloomreach Experience Manager (brXM) versions 4.1.0 through 14.2.2. The vulnerability was discovered in June 2020 and publicly disclosed in March 2021 (Bloomreach Blog).

Technical details

The vulnerability exists in the login portals at both /cms and /cms/console endpoints of the web application. The XSS vulnerability was found in the 'loginmessage' parameter and could be triggered by unauthenticated users. However, logged-in users were not affected as they would be redirected before the 'loginmessage' is displayed (Bloomreach Blog).

Impact

This vulnerability allows unauthenticated attackers to execute arbitrary web scripts or HTML code in the context of the login portal. This could potentially lead to theft of user credentials or session tokens if users interact with the malicious payload (Bloomreach Blog).

Mitigation and workarounds

The vulnerability was fixed in a security update released by Bloomreach in October 2020. Users are advised to update to the latest stable version to address this vulnerability (Bloomreach Blog).

Community reactions

Bloomreach, which powers over $200 billion in digital commerce experiences and serves major organizations including the Dutch Government, Dutch Police, and Dutch Railways, responded promptly to the vulnerability report and coordinated the disclosure process (Bloomreach Blog).

Additional resources


SourceThis report was generated using AI

Related Bloomreach Experience Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-14987HIGH7.2
  • Bloomreach Experience ManagerBloomreach Experience Manager
  • cpe:2.3:a:bloomreach:experience_manager
NoYesMar 11, 2021
CVE-2020-14989MEDIUM6.5
  • Bloomreach Experience ManagerBloomreach Experience Manager
  • cpe:2.3:a:bloomreach:experience_manager
NoYesMar 11, 2021
CVE-2020-14988MEDIUM5.4
  • Bloomreach Experience ManagerBloomreach Experience Manager
  • cpe:2.3:a:bloomreach:experience_manager
NoYesMar 11, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management