PT-2021-2356 · Ibm · Ibm Application Performance Management+1
Published
2021-02-26
·
Updated
2021-03-08
·
CVE-2020-4725
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Monitoring versions 8.1.4
Description
The issue exists due to inadequate protection of the web page structure in IBM Application Performance Management (APM). An attacker, acting remotely, can exploit this to impact data integrity by sending a specially crafted HTTP request. This could allow an authenticated user to modify HTML content, potentially misleading another user.
Recommendations
For version 8.1.4, consider restricting access to the APM UI to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the APM UI for sensitive operations until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Application Performance Management
Ibm Monitoring