CVE-2016-0280
Summary
| CVE | CVE-2016-0280 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-08-08 01:59:00 UTC |
| Updated | 2017-09-01 01:29:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JR55452: XSS VULNERABILITY ALLOWS REMOTE ATTACKS | AIXAPAR | www-01.ibm.com | Vendor Advisory |
| Malformed Request | BID | www.securityfocus.com | |
| IBM InfoSphere Information Server Input Validation Flaw Lets Remote Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Security Bulletin: IBM InfoSphere Information Server is vulnerable to Cross-Site Scripting (XSS) (CVE-2016-0280) | CONFIRM | www-01.ibm.com | Mitigation, Patch, VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.