First published: Sat Oct 03 2015(Updated: )
Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8916.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages | =6.2.0.0 | |
IBM OpenPages | =6.2.1.0 | |
IBM OpenPages | =6.2.1.1 | |
IBM OpenPages | =7.0.0.0 | |
IBM OpenPages | =7.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0144 has been classified as a moderate severity vulnerability due to its ability to allow authenticated users to inject arbitrary web scripts or HTML.
CVE-2015-0144 affects IBM OpenPages GRC Platform versions 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1.
To fix CVE-2015-0144, ensure your IBM OpenPages GRC Platform is updated to the latest version that addresses this vulnerability.
Yes, CVE-2015-0144 can be exploited remotely by authenticated users through crafted URLs.
CVE-2015-0144 is a cross-site scripting (XSS) vulnerability.