Medium Severity

Security Bulletin: Vulnerability affects IBM Watson Assistant for IBM Cloud Pak for Data

Share this post:

DOM-based vulnerability affects IBM Watson (TM) Assistant for IBM Cloud Pak for Data. A DOM-based, cross-site scripting vulnerability was found in the admin console where user input was not validated correctly. An authenticated user could exploit the flaw by injecting JavaScript code into the application in a request, and the payload would be stored. Subsequent navigation to the affected pages would result in the code being executed in the browser.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
Watson Assistant for IBM Cloud Pak for Data 1.0.0 – 1.3.0

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1125585

More stories

Security Bulletin: Vulnerability in Apache Commons Compress affects IBM Spectrum Protect Plus (CVE-2019-12402).

Feb 22, 2020 7:00 pm EST | Medium Severity

A denial of service vulnerability in Apache Commons Compress affects IBM Spectrum Protect Plus. ...read more



Security Bulletin: Multiple vulnerabilities in Linux Kernel affect IBM Spectrum Protect Plus

Feb 22, 2020 7:00 pm EST | Medium Severity

There are multiple security vulnerabilities in the Linux Kernel that affect IBM Spectrum Protect Plus. ...read more