IBM Support

Security Bulletin: Vulnerability affects IBM Watson Assistant for IBM Cloud Pak for Data

Security Bulletin


Summary

DOM-based vulnerability affects IBM Watson (TM) Assistant for IBM Cloud Pak for Data. A DOM-based, cross-site scripting vulnerability was found in the admin console where user input was not validated correctly. An authenticated user could exploit the flaw by injecting JavaScript code into the application in a request, and the payload would be stored. Subsequent navigation to the affected pages would result in the code being executed in the browser.

Vulnerability Details

CVEID:   CVE-2019-4428
DESCRIPTION:   IBM WDC - Watson Assistant is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/162807 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s)Version(s)
Watson Assistant for IBM Cloud Pak for Data1.0.0 - 1.3.0

Remediation/Fixes

Upgrade to IBM Watson Assistant for IBM Cloud Pak for Data 1.4.0. To download the software, go to Passport Advantage, then search for "watson assistant cloud pak data". Select either IBM Watson Assistant for IBM Cloud Pak for Data Installation Packages Linux English eAssembly, part number CC4F1EN, or IBM Watson Assistant for IBM Cloud Pak for Data Add-on V1.4.0, part number CJ6I6EN. Installation instructions for IBM Watson Assistant for IBM Cloud Pak for Data 1.4.0 can be found at https://cloud.ibm.com/docs/services/assistant-data?topic=assistant-data-install-140

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

03 Dec 2019: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU055","label":"Cognitive Applications"},"Product":{"code":"SSWTLZ","label":"IBM Watson Developer Cloud"},"Component":"Watson Assistant","Platform":[{"code":"PF040","label":"RedHat OpenShift"}],"Version":"1.0.0 - 1.3.0","Edition":"ALL","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
20 December 2019

UID

ibm11125585