VYPR
Unrated severityNVD Advisory· Published Jul 13, 2021· Updated Sep 16, 2024

CVE-2021-20366

CVE-2021-20366

Description

IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195037.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Cloud Pak for Applications 4.3 is vulnerable to stored cross-site scripting, allowing authenticated users to inject arbitrary JavaScript, potentially leading to credential disclosure.

Vulnerability

IBM Cloud Pak for Applications version 4.3 is vulnerable to cross-site scripting (XSS) due to improper input validation in the Web UI. An attacker with low-privileged authenticated access can embed arbitrary JavaScript code through the application's interface [1]. The vulnerability affects all deployments of IBM Cloud Pak for Applications v4.3 and is fixed in v4.3.1 [1].

Exploitation

An attacker must have a valid low-privileged user account on the IBM Cloud Pak for Applications instance. The attack vector is network-based (AV:N) and requires user interaction, as the injected script executes in the context of another user's trusted session [1]. The attacker crafts a malicious payload, submits it via the vulnerable input field, and the script is later rendered when a victim user (with higher privileges) views the affected page.

Impact

A successful exploit allows the attacker to execute arbitrary JavaScript in the victim's browser within the security context of the Web UI. This can lead to alteration of intended functionality, disclosure of credentials or session tokens, and unauthorized actions on behalf of the victim. The CVSS score of 5.4 (Medium) reflects the limited scope (changed) and low impact on confidentiality and integrity [1].

Mitigation

IBM released fix version 4.3.1 which remediates the input validation vulnerability [1]. No workarounds or mitigations are provided. Apply the update to all affected deployments of IBM Cloud Pak for Applications v4.3. This issue is not listed on the CISA Known Exploited Vulnerabilities catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.