First published: Sun Jun 28 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the web server in IBM Domino 8.5.x before 8.5.3 FP6 IF8 and 9.x before 9.0.1 FP4, when Webmail is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH9WYPR5.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Domino | =8.5.0 | |
IBM Domino | =8.5.1 | |
IBM Domino | =8.5.2 | |
IBM Domino | =8.5.3 | |
IBM Domino | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1981 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2015-1981, upgrade IBM Domino to version 8.5.3 FP6 IF8 or higher for 8.5.x, or to version 9.0.1 FP4 or higher for 9.x.
CVE-2015-1981 affects remote authenticated users of IBM Domino versions 8.5.x before FP6 IF8 and 9.x before FP4 when Webmail is enabled.
CVE-2015-1981 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.
The potential impacts of CVE-2015-1981 include unauthorized execution of scripts, data theft, and session hijacking.