PT-2021-2356 · Ibm · Ibm Application Performance Management+1

Published

2021-02-26

·

Updated

2021-03-08

·

CVE-2020-4725

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Monitoring versions 8.1.4
Description The issue exists due to inadequate protection of the web page structure in IBM Application Performance Management (APM). An attacker, acting remotely, can exploit this to impact data integrity by sending a specially crafted HTTP request. This could allow an authenticated user to modify HTML content, potentially misleading another user.
Recommendations For version 8.1.4, consider restricting access to the APM UI to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the APM UI for sensitive operations until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01594
CVE-2020-4725

Affected Products

Ibm Application Performance Management
Ibm Monitoring