CVE-2021-20366
Description
IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195037.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Cloud Pak for Applications 4.3 is vulnerable to stored cross-site scripting, allowing authenticated users to inject arbitrary JavaScript, potentially leading to credential disclosure.
Vulnerability
IBM Cloud Pak for Applications version 4.3 is vulnerable to cross-site scripting (XSS) due to improper input validation in the Web UI. An attacker with low-privileged authenticated access can embed arbitrary JavaScript code through the application's interface [1]. The vulnerability affects all deployments of IBM Cloud Pak for Applications v4.3 and is fixed in v4.3.1 [1].
Exploitation
An attacker must have a valid low-privileged user account on the IBM Cloud Pak for Applications instance. The attack vector is network-based (AV:N) and requires user interaction, as the injected script executes in the context of another user's trusted session [1]. The attacker crafts a malicious payload, submits it via the vulnerable input field, and the script is later rendered when a victim user (with higher privileges) views the affected page.
Impact
A successful exploit allows the attacker to execute arbitrary JavaScript in the victim's browser within the security context of the Web UI. This can lead to alteration of intended functionality, disclosure of credentials or session tokens, and unauthorized actions on behalf of the victim. The CVSS score of 5.4 (Medium) reflects the limited scope (changed) and low impact on confidentiality and integrity [1].
Mitigation
IBM released fix version 4.3.1 which remediates the input validation vulnerability [1]. No workarounds or mitigations are provided. Apply the update to all affected deployments of IBM Cloud Pak for Applications v4.3. This issue is not listed on the CISA Known Exploited Vulnerabilities catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: = 4.3
- IBM/Cloud Pak for Applicationsv5Range: 4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/195037mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6471337mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.