VYPR
Unrated severityNVD Advisory· Published May 4, 2021· Updated Sep 17, 2024

CVE-2020-4987

CVE-2020-4987

Description

The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored cross-site scripting in IBM FlashSystem 900 user management GUI allows credential disclosure; fixed in versions 1.5.2.9 and 1.6.1.3.

Vulnerability

The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting (XSS) in code versions 1.5.2.8 and prior, and 1.6.1.2 and prior [1]. Affected system types include FlashSystem 900 MTMs 9840-AE1, 9843-AE1, 9840-AE2, 9843-AE2, 9840-AE3, and 9843-AE3 [1]. The vulnerability allows users to embed arbitrary JavaScript code into the Web UI, which is then stored and executed in the context of other users' sessions.

Exploitation

An attacker with authenticated access to the management GUI can inject malicious JavaScript via the user management functionality. The injected script is stored and subsequently executed when other users (including administrators) access the affected page. No additional user interaction is required beyond visiting the compromised page. The attacker does not need network-level access beyond what is required to reach the management interface.

Impact

Successful exploitation enables the attacker to alter the intended functionality of the Web UI, potentially leading to disclosure of credentials (e.g., session tokens) within a trusted session. The CVSS 3.0 base score is 6.4 (medium), with vectors AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N [1], indicating limited impact on confidentiality and integrity with scope change.

Mitigation

IBM has released fixed firmware versions: 1.5.2.9 for the 1.5 stream and 1.6.1.3 for the 1.6 stream [1]. Users should upgrade to these or later versions via IBM Fix Central. FlashSystem 840 systems (MTM AE1) are no longer supported and should be upgraded. No workaround other than upgrading is recommended [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • IBM/FlashSystemllm-fuzzy2 versions
    <=1.5.2.8, <=1.6.1.2+ 1 more
    • (no CPE)range: <=1.5.2.8, <=1.6.1.2
    • (no CPE)range: 1.6.1.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.