IBM Support

JR62961: SECURITY APAR - CVE-2020-4051 AFFECTS IBM BUSINESS AUTOMATION STUDIO

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • CVEID: CVE-2020-4051
    DESCRIPTION: In Dijit before versions 1.11.11, and greater than
    or equal to 1.12.0 and less than 1.12.9, and greater than or
    equal to 1.13.0 and less than 1.13.8, and greater than or equal
    to 1.14.0 and less than 1.14.7, and greater than or equal to
    1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0
    and less than 1.16.3, there is a cross-site scripting
    vulnerability in the Editor's LinkDialog plugin. This has been
    fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.
    CVSS Base score: 6.1
    CVSS Temporal Score:
    See:https://exchange.xforce.ibmcloud.com/vulnerabilities/183740
    for the current score.
    CVSS Vector: ( CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
    

Local fix

Problem summary

  • No additional information is available.
    
    PRODUCTS AFFECTED
    IBM Cloud Pack for Automaton - Business Automation Studio
    

Problem conclusion

  • A fix is available for the latest fix pack as well as the latest
     release of Business Automaton Studio.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR62961

  • Reported component name

    CLOUD PAK FOR A

  • Reported component ID

    5737I2300

  • Reported release

    K00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-10-30

  • Closed date

    2021-02-04

  • Last modified date

    2021-02-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    CLOUD PAK FOR A

  • Fixed component ID

    5737I2300

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBYVB","label":"IBM Cloud Pak for Business Automation"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"K00","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
11 March 2022