CVE-2015-1979: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to the (1) addressability or (2) comments component.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1979?
CVE-2015-1979 is considered to be a medium-severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2015-1979?
To fix CVE-2015-1979, upgrade IBM Case Manager to version 5.2.1.2 or later.
What are the potential impacts of CVE-2015-1979?
The potential impacts of CVE-2015-1979 include unauthorized script execution and data theft from authenticated users.
Who is affected by CVE-2015-1979?
CVE-2015-1979 affects remote authenticated users of IBM Case Manager versions 5.2.1 and 5.2.1.1.
What components are involved in CVE-2015-1979?
CVE-2015-1979 involves multiple components including the addressability and comments sections of the IBM Case Manager Error dialog.