IBM Support

IV46530: CROSS SITE SCRIPTING (XSS) VULNERABILITY WITH SELF SERVICE UI

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Steps to Recreate Problem:
    1) Logon to Self Service UI
    2) Create a Project
    3) Enter a description of
    <script>alert(document.cookie)</script>
    4) Click on the Project name in the projects portlet
    A popup is displayed showing the cookie information (using
    Firefox 3.6.12)
    

Local fix

Problem summary

  • Problem summary: *
    Special Character Validation
    

Problem conclusion

  • Conclusion: *
    Provided SImpleSRM.war file with validations
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV46530

  • Reported component name

    TSAM (& INSTALL

  • Reported component ID

    5724W7800

  • Reported release

    723

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2013-08-02

  • Closed date

    2013-10-14

  • Last modified date

    2013-10-14

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TSAM (& INSTALL

  • Fixed component ID

    5724W7800

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSFG5E","label":"Tivoli Service Automation Manager"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"723"}]

Document Information

Modified date:
09 November 2020