IBM Support

JR62944: SECURITY APAR - CVE-2020-4051 AND CVE-2018-6561 VULNERABILITIES WERE IDENTIFIED

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • CVEID:   CVE-2020-4051
    DESCRIPTION:   Dijit is vulnerable to cross-site scripting,
    caused by improper validation of user-supplied input by the
    Editor's LinkDialog plugin. A remote attacker could exploit this
    vulnerability to inject malicious script into a Web page which
    would be executed in a victim's web browser within the security
    context of the hosting website, once the page is viewed. An
    attacker could use this vulnerability to steal the victim's
    cookie-based authentication credentials.
    CVSS Base score: 6.1
    CVSS Temporal Score: See:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/183740 for
    the current score.
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
    
    CVEID:   CVE-2018-6561
    DESCRIPTION:   Dojo Toolkit is vulnerable to cross-site
    scripting in dijit.Editor, caused by improper validation of
    user-supplied input. A remote attacker could exploit this
    vulnerability using the 'onload' attribute of an SVG element to
    inject malicious script into a Web page which would be executed
    in a victim's Web browser within the security context of the
    hosting Web site, once the page is viewed. An attacker could use
    this vulnerability to steal the victim's cookie-based
    authentication credentials.
    CVSS Base score: 6.1
    CVSS Temporal Score: See:
    https://exchange.xforce.ibmcloud.com/vulnerabilities/138648 for
    the current score.
    CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
    
    PRODUCTS AFFECTED
    IBM Cloud Pak for Automation - Business Automation Application
    IBM Cloud Pak for Automation - Business Automation Studio
    IBM Cloud Pak for Automation - Business Automation Workflow
    IBM Business Automation Workflow
    

Local fix

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix is available for the last fix pack of all affected
    supported releases as well as the last two releases of Single
    Stream Continuous Delivery (SSCD).
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR62944

  • Reported component name

    CLOUD PAK FOR A

  • Reported component ID

    5737I2300

  • Reported release

    K00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-10-30

  • Closed date

    2021-01-29

  • Last modified date

    2021-01-29

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    CLOUD PAK FOR A

  • Fixed component ID

    5737I2300

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBYVB","label":"IBM Cloud Pak for Business Automation"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"K00","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
11 March 2022