CVE-2016-0261
Summary
| CVE | CVE-2016-0261 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-12 21:29:00 UTC |
| Updated | 2018-04-09 14:57:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Care Management | 6.0 | All | All | All |
| Application | Ibm | Care Management | 6.0 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.0 | sp1 | All | All |
| Application | Ibm | Curam Social Program Management | 6.0 | sp2 | All | All |
| Application | Ibm | Curam Social Program Management | 6.0.0 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.0.0 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.0.1 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.1.0 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.1.1 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.0 | sp1 | All | All |
| Application | Ibm | Curam Social Program Management | 6.0 | sp2 | All | All |
| Application | Ibm | Curam Social Program Management | 6.0.0 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.0.0 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.0.1 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.1.0 | All | All | All |
| Application | Ibm | Curam Social Program Management | 6.1.1.1 | All | All | All |
| Application | Ibm | Curam Social Program Management | All | All | All | All |
| Application | Ibm | Curam Social Program Management | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: Fix available for Vulnerability in Cross-Site Scripting (XSS) affecting IBM Cúram Social Program Management (CVE-2016-0261) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.