Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM SmartCloud Analytics Log Analysis 跨站脚本漏洞
Vulnerability Description
IBM SmartCloud Analytics Log Analysis是美国IBM公司的一套通过对非结构化数据进行分析以帮助发现、隔离和解决问题的软件。 IBM SmartCloud Analytics Log Analysis 1.1和1.2版本中存在跨站脚本漏洞,该漏洞源于Oauth授权端会在响应中返回无效的参数。远程攻击者可借助无效的‘query’参数利用该漏洞注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A