Learn about CVE-2020-4615 affecting IBM Data Risk Manager 2.0.6. Understand the impact, technical details, and mitigation steps for this cross-site scripting vulnerability.
IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting, potentially leading to credentials disclosure within a trusted session.
Understanding CVE-2020-4615
IBM Data Risk Manager version 2.0.6 is affected by a cross-site scripting vulnerability that allows attackers to inject arbitrary JavaScript code into the Web UI.
What is CVE-2020-4615?
IBM Data Risk Manager (iDNA) 2.0.6 is susceptible to cross-site scripting (XSS) attacks.
Attackers can exploit this vulnerability to insert malicious JavaScript code into the Web UI.
This manipulation can alter the intended functionality, possibly resulting in the disclosure of credentials within a trusted session.
The Impact of CVE-2020-4615
CVSS Base Score: 5.4 (Medium Severity)
Attack Vector: Network
Exploit Code Maturity: High
User Interaction: Required
Privileges Required: Low
Scope: Changed
Confidentiality Impact: Low
Integrity Impact: Low
Availability Impact: None
Temporal Score: 5.2 (Medium Severity)
Technical Details of CVE-2020-4615
IBM Data Risk Manager version 2.0.6 is affected by the following: