PT-2021-12269 · Ibm · Ibm Flashsystem 900

Antoine Enard

+2

·

Published

2021-05-04

·

Updated

2022-01-01

·

CVE-2020-4987

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM FlashSystem 900 versions 1.5.2.8 and prior IBM FlashSystem 900 versions 1.6.1.2 and prior
Description The issue concerns stored cross-site scripting in the user management GUI, allowing users to embed arbitrary JavaScript code in the Web UI. This could alter the intended functionality, potentially leading to credentials disclosure within a trusted session.
Recommendations For versions 1.5.2.8 and prior, update to a version later than 1.5.2.8 to resolve the issue. For versions 1.6.1.2 and prior, update to a version later than 1.6.1.2 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4987

Affected Products

Ibm Flashsystem 900