CVE-2020-4987Cross-site Scripting in IBM Flashsystem 900 Firmware

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 71.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateMay 24

Description

The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDibm/flashsystem_900_firmware1.6.0.01.6.1.3+1
CVEListV5ibm/flashsystem_9001.5.2.8, 1.6.1.2+1

🔴Vulnerability Details

2
GHSA
GHSA-ccmm-6836-3vxj: IBM FlashSystem 900 12022-05-24
CVEList
CVE-2020-4987: The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 12021-05-04
CVE-2020-4987 — Cross-site Scripting in IBM | cvebase