CVE-2015-1968: XSS
Published Jul 20, 2015
·Updated
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
5 affected components
IBM InfoSphere Master Data Management=9.1
IBM InfoSphere Master Data Management=10.1
IBM InfoSphere Master Data Management=11.0
IBM InfoSphere Master Data Management=11.3
IBM InfoSphere Master Data Management=11.4
Remediation
Patch Available
Event History
Jul 20, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1968?
CVE-2015-1968 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-1968?
To fix CVE-2015-1968, upgrade to IBM InfoSphere Master Data Management version 11.4 FP03 or later.
3
Which versions are affected by CVE-2015-1968?
CVE-2015-1968 affects IBM InfoSphere Master Data Management versions 9.1, 10.1, 11.0, 11.3, and 11.4 prior to FP03.
4
What type of vulnerability is CVE-2015-1968?
CVE-2015-1968 is a cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2015-1968?
CVE-2015-1968 can be exploited by remote authenticated users.