VYPR
Unrated severityNVD Advisory· Published Jul 13, 2021· Updated Sep 16, 2024

CVE-2021-20365

CVE-2021-20365

Description

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195036.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting, allowing users to embed arbitrary JavaScript and potentially disclose credentials.

Vulnerability

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting (XSS) due to improper sanitization of user input in the Web UI, as reported in [1]. The vulnerability allows users to embed arbitrary JavaScript code, potentially altering intended functionality. All versions of IBM Cloud Pak for Applications are affected, with version 4.3 specifically mentioned in the CVE [1].

Exploitation

An attacker with low privileges can craft a script injection that executes when a victim views the malicious content, requiring user interaction. The CVSS vector (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) indicates the attacker needs network access and user interaction to trigger the script [1]. The attacker may embed JavaScript in anchor tags with target="_blank" attributes, leading to script execution in the victim's session.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to disclosure of credentials or session tokens. The impact is limited to low confidentiality and integrity compromise within the browser session [1].

Mitigation

IBM recommends upgrading to IBM Cloud Pak for Applications 4.3.1, which fixes the vulnerability by sanitizing user input and preventing arbitrary JavaScript execution [1]. No workarounds are available. The vulnerability is not listed on CISA's known exploited vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.