Stored Cross-Site Scripting Vulnerability in IBM Jazz for Service Management and Tivoli Netcool/OMNIbus_GUI
CVE-2021-29833
6.4MEDIUM
What is CVE-2021-29833?
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI are susceptible to stored cross-site scripting vulnerabilities. This allows attackers to inject malicious JavaScript code into the web interface, which can then be executed in the context of users' sessions. As a result, this vulnerability poses serious risks including potential credential disclosure and the alteration of normal user interactions within a trusted environment. Users are advised to apply the necessary patches and review security configurations to mitigate risks associated with this vulnerability.
Affected Version(s)
Jazz for Service Management 1.1.3.10