First published: Mon Jul 20 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to the (1) addressability or (2) comments component.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Case Manager | =5.2.1 | |
IBM Case Manager | =5.2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1979 is considered to be a medium-severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2015-1979, upgrade IBM Case Manager to version 5.2.1.2 or later.
The potential impacts of CVE-2015-1979 include unauthorized script execution and data theft from authenticated users.
CVE-2015-1979 affects remote authenticated users of IBM Case Manager versions 5.2.1 and 5.2.1.1.
CVE-2015-1979 involves multiple components including the addressability and comments sections of the IBM Case Manager Error dialog.