CVE-2016-0223
Summary
| CVE | CVE-2016-0223 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-15 22:29:00 UTC |
| Updated | 2018-04-09 12:23:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Forms Server | 4.0.0.0 | All | All | All |
| Application | Ibm | Forms Server | 8.0.0.0 | All | All | All |
| Application | Ibm | Forms Server | 8.0.1.0 | All | All | All |
| Application | Ibm | Forms Server | 8.1.0.0 | All | All | All |
| Application | Ibm | Forms Server | 8.2.0.0 | All | All | All |
| Application | Ibm | Forms Server | 4.0.0.0 | All | All | All |
| Application | Ibm | Forms Server | 8.0.0.0 | All | All | All |
| Application | Ibm | Forms Server | 8.0.1.0 | All | All | All |
| Application | Ibm | Forms Server | 8.1.0.0 | All | All | All |
| Application | Ibm | Forms Server | 8.2.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM Forms Server vulnerability identified in Webform Server (CVE-2016-0223) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.