ASA-2019-00255 – IBM Planning Analytics: Cross-Site Scripting (XSS) vulnerability in Dojo Toolkit


Allele Security Alert

ASA-2019-00255

Identifier(s)

ASA-2019-00255, CVE-2018-15494

Title

Cross-Site Scripting (XSS) vulnerability in Dojo Toolkit

Vendor(s)

IBM

Product(s)

IBM Planning Analytics

Affected version(s)

IBM Planning Analytics versions 2.0, 2.0.1, 2.0.2 ,2.0.3, 2.0.4, 2.0.5 and 2.0.6

Fixed version(s)

IBM Planning Analytics version 2.0.7

Proof of concept

Unknown

Description

Dojo Toolkit is vulnerable to Cross-Site Scripting (XSS), caused by improper validation of user-supplied input by the DataGrid component. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Technical details

Unknown

Credits

Unknown

Reference(s)

Security Bulletin: Multiple vulnerabilities affect IBM Planning Analytics
https://www-01.ibm.com/support/docview.wss?uid=ibm10879407

Dojo Toolkit DataGrid component cross-site scripting
https://exchange.xforce.ibmcloud.com/vulnerabilities/148556

CVE-2018-15494
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15494

CVE-2018-15494
https://nvd.nist.gov/vuln/detail/CVE-2018-15494

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: May 3, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.