Vulnerability Details CVE-2021-38961
IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212049.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.6%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-38961
-
cpe:2.3:h:ibm:power_system_ac922_(8335-gtc):-
-
cpe:2.3:h:ibm:power_system_ac922_(8335-gtg):-
-
cpe:2.3:h:ibm:power_system_ac922_(8335-gtw):-
-
cpe:2.3:o:ibm:power_system_ac922_(8335-gtc)_firmware:op910
-
cpe:2.3:o:ibm:power_system_ac922_(8335-gtg)_firmware:op910
-
cpe:2.3:o:ibm:power_system_ac922_(8335-gtw)_firmware:op910