CVE-2021-20365
Description
IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195036.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting, allowing users to embed arbitrary JavaScript and potentially disclose credentials.
Vulnerability
IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting (XSS) due to improper sanitization of user input in the Web UI, as reported in [1]. The vulnerability allows users to embed arbitrary JavaScript code, potentially altering intended functionality. All versions of IBM Cloud Pak for Applications are affected, with version 4.3 specifically mentioned in the CVE [1].
Exploitation
An attacker with low privileges can craft a script injection that executes when a victim views the malicious content, requiring user interaction. The CVSS vector (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) indicates the attacker needs network access and user interaction to trigger the script [1]. The attacker may embed JavaScript in anchor tags with target="_blank" attributes, leading to script execution in the victim's session.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to disclosure of credentials or session tokens. The impact is limited to low confidentiality and integrity compromise within the browser session [1].
Mitigation
IBM recommends upgrading to IBM Cloud Pak for Applications 4.3.1, which fixes the vulnerability by sanitizing user input and preventing arbitrary JavaScript execution [1]. No workarounds are available. The vulnerability is not listed on CISA's known exploited vulnerabilities (KEV) catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: = 4.3
- IBM/Cloud Pak for Applicationsv5Range: 4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/195036mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6471345mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.