CVE-2014-0913: XSS
Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0913?
CVE-2014-0913 has been identified with a moderate severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-0913?
To fix CVE-2014-0913, upgrade to IBM Domino 8.5.3 FP6 IF2 or later, or 9.0.1 FP1 or later.
What software is affected by CVE-2014-0913?
CVE-2014-0913 affects IBM Lotus Domino versions 8.5.3 FP6 before IF2 and 9.0.1 before FP1, as well as IBM Lotus iNotes 8.5.3 FP6 and 9.0.1.
What impact does CVE-2014-0913 have on users?
CVE-2014-0913 allows remote attackers to inject arbitrary web scripts or HTML into emails, potentially compromising user security.
Is there a workaround for CVE-2014-0913?
While the best solution is to update the affected software, temporarily disabling features that process email HTML can mitigate the risk.