VYPR
Unrated severityNVD Advisory· Published Mar 14, 2022· Updated Sep 16, 2024

CVE-2021-39055

CVE-2021-39055

Description

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214534.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 contains a stored XSS vulnerability enabling arbitrary JavaScript execution and potential credential disclosure.

Vulnerability

IBM Spectrum Copy Data Management versions 2.2.0.0 through 2.2.14.3 contain a cross-site scripting (XSS) vulnerability in the Web UI. This flaw allows authenticated users with appropriate privileges to embed arbitrary JavaScript code, which is then executed in the context of other users' sessions [1]. The vulnerability is classified as a stored XSS issue, as the injected script persists in the application and triggers when other users access the affected interface.

Exploitation

An attacker must have a valid user account with permissions to access the Web UI components that accept and store unsanitized input. The attacker crafts a malicious script payload and submits it via a vulnerable input field (e.g., configuration parameters or form data). When another user, including a privileged administrator, views the affected page or interface, the injected JavaScript executes in their browser session. No additional user interaction beyond viewing the page is required for script execution [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session within the IBM Spectrum Copy Data Management Web UI. This can alter the intended functionality of the interface, potentially leading to disclosure of sensitive session credentials, such as authentication tokens or cookies. The attacker may also be able to perform actions on behalf of the victim, depending on the capabilities exposed by the injected script. The CVSS vector (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) indicates low confidentiality and integrity impact with a scope change [1].

Mitigation

IBM released a fixed version to address this vulnerability. The security bulletin advises upgrading to IBM Spectrum Copy Data Management version 2.2.14.4 or later (see the IBM support page for exact version details). There is no known workaround that fully mitigates the vulnerability without applying the patch. Users should apply the update as soon as possible to prevent exploitation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.