IBM Support

JR50791: SCRIPT COULD BE INJECTED INTO INSTANCES WIDGET

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as fixed if next.

Error description

  • You perform testing related to the Instances widget and notice
    that a script can be injected into the instances.jsp file.
    Depending on the script content, the injected script could cause
    the Instances widget to behave abnormally.
    
    PRODUCT AFFECTED:
    IBM Business Monitor
    

Local fix

Problem summary

  • The script checking within the instances.jsp file was not
    complete.
    

Problem conclusion

  • A fix will be incorporated into a later release that prevents
    scripts from being injected into the Instances widget through
    the instances.jsp file.
    

Temporary fix

  • Not applicable
    

Comments

APAR Information

  • APAR number

    JR50791

  • Reported component name

    WEB BUS MONITOR

  • Reported component ID

    5724M2400

  • Reported release

    801

  • Status

    CLOSED FIN

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2014-07-14

  • Closed date

    2014-09-10

  • Last modified date

    2014-09-10

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

Applicable component levels

  • R801 PSN

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSSRR3","label":"WebSphere Business Monitor"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"801","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 October 2021