First published: Sun Oct 04 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the Projects page in IBM UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM UrbanCode Build | =6.1.0.0 | |
IBM UrbanCode Build | =6.1.0.1 | |
IBM UrbanCode Build | =6.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1983 has a medium severity level due to its potential for enabling cross-site scripting attacks affecting authenticated users.
To fix CVE-2015-1983, you should upgrade IBM UrbanCode Build to version 6.1.1 or later where this vulnerability is addressed.
Authenticated users of IBM UrbanCode Build versions 6.1.0.0 to 6.1.0.2 are susceptible to the vulnerabilities outlined in CVE-2015-1983.
CVE-2015-1983 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
There are no official workarounds for CVE-2015-1983; the recommended solution is to upgrade to a patched version.