
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 were identified as vulnerable to cross-site scripting (XSS). The vulnerability was discovered in late 2019 and publicly disclosed in September 2020. This security flaw allows attackers to embed arbitrary JavaScript code in the Web UI, potentially compromising the intended functionality of the application (IBM Security).
The vulnerability has been assigned a CVSS Base score of 5.4 with the vector (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). The attack requires network access, low attack complexity, low privileges, and user interaction. The scope is changed with low impact on confidentiality and integrity, but no impact on availability (IBM Security).
When exploited, this vulnerability enables attackers to alter the intended functionality of the Web UI by injecting malicious JavaScript code. The primary risk is the potential disclosure of credentials within a trusted session, which could lead to unauthorized access to sensitive information (IBM Security).
The vulnerability requires low attack complexity and low privileges for exploitation, but does need user interaction to be successful. The attack vector is network-based, indicating that the vulnerability can be exploited remotely (IBM Security).
IBM has released several fixes depending on the version affected. For V9.0.0.0 through 9.0.5.5, users can either upgrade to Fix Pack 9.0.5.6 or later, or apply Interim Fix PH26220. For V8.5.0.0 through 8.5.5.17, the recommendation is to upgrade to Fix Pack 8.5.5.18 or later, or apply Interim Fix PH26220. Users of V8.0.0.0 through 8.0.0.15 should upgrade to 8.0.0.15 and apply Interim Fix PH26220. For V7.0.0.0 through 7.0.0.45, users should upgrade to 7.0.0.45 and apply Interim Fix PH26220. No workarounds are available (IBM Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."