IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cloud_pak_system | Ibm | 2.3.4.0 (including) | 2.3.4.0 (including) |
| Cloud_pak_system | Ibm | 2.3.4.1 (including) | 2.3.4.1 (including) |
| Cloud_pak_system | Ibm | 2.3.4.1-ifix1 (including) | 2.3.4.1-ifix1 (including) |
| Cloud_pak_system | Ibm | 2.3.5.0 (including) | 2.3.5.0 (including) |
| Cloud_pak_system | Ibm | 2.3.6.0 (including) | 2.3.6.0 (including) |
| Os_image_for_red_hat_linux_systems | Ibm | 4.0.4.0 (including) | 4.0.4.0 (including) |
| Os_image_for_red_hat_linux_systems | Ibm | 4.0.5.0 (including) | 4.0.5.0 (including) |
| Os_image_for_red_hat_linux_systems | Ibm | 4.0.6.0 (including) | 4.0.6.0 (including) |
| Os_image_for_red_hat_linux_systems | Ibm | 4.0.7.0 (including) | 4.0.7.0 (including) |
| Os_image_for_red_hat_linux_systems | Ibm | 5.0.0.0 (including) | 5.0.0.0 (including) |
| Os_image_for_red_hat_linux_systems | Ibm | 5.0.1.0 (including) | 5.0.1.0 (including) |