CVE-2015-0144: XSS
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8916.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0144?
CVE-2015-0144 has been classified as a moderate severity vulnerability due to its ability to allow authenticated users to inject arbitrary web scripts or HTML.
What software versions are affected by CVE-2015-0144?
CVE-2015-0144 affects IBM OpenPages GRC Platform versions 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1.
How do I fix CVE-2015-0144?
To fix CVE-2015-0144, ensure your IBM OpenPages GRC Platform is updated to the latest version that addresses this vulnerability.
Can CVE-2015-0144 be exploited remotely?
Yes, CVE-2015-0144 can be exploited remotely by authenticated users through crafted URLs.
What type of vulnerability is CVE-2015-0144?
CVE-2015-0144 is a cross-site scripting (XSS) vulnerability.