Cross-Site Scripting Vulnerability in IBM WebSphere Application Server - Liberty
CVE-2020-4303

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
2 April 2020

What is CVE-2020-4303?

The IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 20.0.0.3 contain a vulnerability that allows for cross-site scripting (XSS) attacks. This issue permits attackers to inject arbitrary JavaScript code into the web user interface. As a result, an attacker could manipulate the application's intended behavior, potentially exposing user credentials during an active session. This vulnerability poses a serious risk as it can be exploited without the need for authentication, affecting the integrity and confidentiality of user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WebSphere Application Server Liberty 17.0.0.3

WebSphere Application Server Liberty 20.0.0.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.