First published: Fri May 09 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Domino R5 | =8.5.3.6 | |
IBM Lotus Domino R5 | =9.0.1.0 | |
IBM iNotes | =8.5.3.6 | |
IBM iNotes | =9.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0913 has been identified with a moderate severity level due to its potential for cross-site scripting attacks.
To fix CVE-2014-0913, upgrade to IBM Domino 8.5.3 FP6 IF2 or later, or 9.0.1 FP1 or later.
CVE-2014-0913 affects IBM Lotus Domino versions 8.5.3 FP6 before IF2 and 9.0.1 before FP1, as well as IBM Lotus iNotes 8.5.3 FP6 and 9.0.1.
CVE-2014-0913 allows remote attackers to inject arbitrary web scripts or HTML into emails, potentially compromising user security.
While the best solution is to update the affected software, temporarily disabling features that process email HTML can mitigate the risk.