漏洞信息详情
ibm administration console for content platform engine filenet content manager 跨站脚本漏洞
漏洞简介
IBM Administration Console for Content Platform Engine(ACCE)是美国IBM公司的一款基于Web的、用于Content Platform Engine工作流管理组件的管理控制台程序。FileNet Content Manager是其中的一个内容管理器。
IBM ACCE中的FileNet Content Manager 5.5.3版本和5.5.4版本中存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.ibm.com/support/pages/node/6208453
参考网址
来源:CONFIRM
链接:https://www.ibm.com/support/pages/node/6208453
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/181227
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-with-administration-console-for-content-platform-engine-component-in-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-security-vulnerabilities-in-filenet-content-manager-2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-security-vulnerabilities-in-filenet-content-manager/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-with-administration-console-for-content-platform-engine-component-in-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-4447
来源:www.nsfocus.net
链接:http://www.nsfocus.net/vulndb/49246
受影响实体
暂无
补丁
- IBM Administration Console for Content Platform Engine FileNet Content Manager 跨站脚本漏洞的修复措施<!--2020-7-22-->
还没有评论,来说两句吧...