Allele Security Alert
ASA-2019-00255
Identifier(s)
ASA-2019-00255, CVE-2018-15494
Title
Cross-Site Scripting (XSS) vulnerability in Dojo Toolkit
Vendor(s)
IBM
Product(s)
IBM Planning Analytics
Affected version(s)
IBM Planning Analytics versions 2.0, 2.0.1, 2.0.2 ,2.0.3, 2.0.4, 2.0.5 and 2.0.6
Fixed version(s)
IBM Planning Analytics version 2.0.7
Proof of concept
Unknown
Description
Dojo Toolkit is vulnerable to Cross-Site Scripting (XSS), caused by improper validation of user-supplied input by the DataGrid component. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Technical details
Unknown
Credits
Unknown
Reference(s)
Security Bulletin: Multiple vulnerabilities affect IBM Planning Analytics
https://www-01.ibm.com/support/docview.wss?uid=ibm10879407
Dojo Toolkit DataGrid component cross-site scripting
https://exchange.xforce.ibmcloud.com/vulnerabilities/148556
CVE-2018-15494
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15494
CVE-2018-15494
https://nvd.nist.gov/vuln/detail/CVE-2018-15494
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: May 3, 2019