IBM InfoSphere Master Data Management Server CVE-2016-9715 Cross Site Scripting Vulnerability
BID:100025
Info
IBM InfoSphere Master Data Management Server CVE-2016-9715 Cross Site Scripting Vulnerability
| Bugtraq ID: | 100025 |
| Class: | Input Validation Error |
| CVE: |
CVE-2016-9715 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2017 12:00AM |
| Updated: | Jul 27 2017 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM InfoSphere Master Data Management Server 11.6 IBM InfoSphere Master Data Management Server 11.5 IBM InfoSphere Master Data Management Server 11.4 IBM InfoSphere Master Data Management Server 11.3 IBM InfoSphere Master Data Management Server 11.0 |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Master Data Management Server CVE-2016-9715 Cross Site Scripting Vulnerability
IBM InfoSphere Master Data Management Server is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
IBM InfoSphere Master Data Management Server is prone to a cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
References
IBM InfoSphere Master Data Management Server CVE-2016-9715 Cross Site Scripting Vulnerability
References:
References: