IBM Support

JR63149: BUSINESS SPACE HELP CAN BE SUSCEPTIBLE TO CROSS-SITE SCRIPTING

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

Direct link to fix

 

APAR status

  • Closed as program error.

Error description

  • The URL /BusinessSpaceHelp/advanced/contentToolbar.jsp can be
    susceptible to cross-site scripting
    
    PRODUCSTS AFFECTED
    IBM Business Automation Workflow
    

Local fix

  • Stop or uninstall the BSpaceHelp application.
    

Problem summary

  • No additional information is available.
    

Problem conclusion

  • A fix is available or will be available that sanitizes the title
     text preventing the potential susceptibility.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR63149

  • Reported component name

    BUS AUTO WORKFL

  • Reported component ID

    5737H4100

  • Reported release

    K00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-12-15

  • Closed date

    2021-05-31

  • Last modified date

    2021-06-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    BUS AUTO WORKFL

  • Fixed component ID

    5737H4100

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SS8JB4","label":"IBM Business Automation Workflow"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"20.0.0.1"}]

Document Information

Modified date:
21 June 2021