CVE-2014-8916: XSS
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0144.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8916?
CVE-2014-8916 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks by authenticated users.
How do I fix CVE-2014-8916?
To fix CVE-2014-8916, upgrade IBM OpenPages GRC Platform to a version that includes the fix, specifically versions 6.2 IF7, 6.2.1.1 IF5, 7.0 FP4, or 7.1 FP1 and later.
What platforms are affected by CVE-2014-8916?
CVE-2014-8916 affects IBM OpenPages GRC Platform versions 6.2.0.0, 6.2.1.0, 6.2.1.1, 7.0.0.0, and 7.1.0.0.
Who is impacted by CVE-2014-8916?
Remote authenticated users of the affected IBM OpenPages GRC Platform versions are impacted by CVE-2014-8916.
What type of vulnerability is CVE-2014-8916?
CVE-2014-8916 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.