QID 376086
Date Published: 2021-11-18
QID 376086: IBM Security SiteProtector SystemCross-Site Scripting (XSS) Vulnerability (6515054)
IBM Security SiteProtector System is a centralized management system that unifies management and analysis for network, server and endpoint security agents and appliances. It reduces the cost and complexity of security management, helps you monitor and measure your exposure to vulnerabilities and demonstrate regulatory compliance. IBM Security SiteProtector system can help minimize your overall risk and increase the efficacy of your security team, while optimizing cost efficiency.
Affected Versions:
IBM Security SiteProtector System 3.1.1
QID Detection Logic:
This QID detects the vulnerable version by checking the file version of SPLogAgent.exe in the installed directory
This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
- IBM Security Advisory -
www.ibm.com/support/pages/node/6515054
CVEs related to QID 376086
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM Security SiteProtector System |
|