Cross-site scripting in Enterprise Security API - CVE-2022-24891
Published: May 20, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in org.owasp.esapi:esapi. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Cloud Pak for Security (CP4S)
IBM Data Risk Manager
Oracle BI Publisher
IBM OpenPages with Watson
Ubuntu
Cloud Foundry UAA
Bosh Release for the UAA
libowasp-esapi-java (Ubuntu package)
How to mitigate CVE-2022-24891
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Data Risk Manager - update to 2.0.6.15
IBM OpenPages with Watson - update to 9.0.0.5.3
Cloud Foundry UAA - update to 75.20.0
Bosh Release for the UAA - update to 75.20.0
libowasp-esapi-java (Ubuntu package) - addressed in versions 2.1.0-2ubuntu0.1~esm1, 2.1.0-3ubuntu0.18.04.1~esm1, 2.1.0-3ubuntu0.20.04.1~esm1, 2.2.3.1-1ubuntu0.1~esm1, 2.4.0.0-2ubuntu0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in OWASP Enterprise Security API
- Multiple vulnerabilities in Cloud Foundry uaa-release
- Multiple vulnerabiities in Cloud Foundry UAA
- Multiple vulnerabilities in IBM Data Risk Manager
- Multiple vulnerabilities in Oracle BI Publisher
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM OpenPages
- Ubuntu update for libowasp-esapi-java