Vulnerability Details
Basic Information
| Title | Security Bulletin: XSS vulnerability affects IBM Cloud Object Storage System (CVE-2021-39014) |
|---|---|
| Type | ibm |
| Published | 2025-04-29T02:13:02 |
| Last Seen | 2025-04-29T11:06:09 |
| CVSS Score | 6.4 (MEDIUM) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2021-39014 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
XSS vulnerability affects IBM Cloud Object Storage System (CVE-2021-39014). This vulnerability has been addressed in the latest ClevOS releases.
## Vulnerability Details
**CVEID:**CVE-2021-39014
**DESCRIPTION:** IBM Cloud Object System is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base score: 6.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213650 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N)
## Affected Products and Versions
Affected Product(s) | Version(s)
—|—
IBM Cloud Object Storage System | 3.15.8.97 or Prior Release
## Remediation/Fixes
**IBM COS Release** | **_Fixing VRM Level_** | **Platform** | **Link to Fix/ Fix Availability Target**
—|—|—|—
3.15 | 3.15.8.106 | CLEVOS | https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Cloud+Object+Storage+System&release=3.15.8.106&platform=All&function=all
3.16 | 3.16.0.47 | CLEVOS | https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Cloud+Object+Storage+System&release=3.16.0.47&platform=All&function=all
## Workarounds and Mitigations
None
##
Impact Assessment
| Base Score | 6.4 |
|---|---|
| Severity | MEDIUM |