First published: Tue Mar 20 2018(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108355.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | <=3.0.1.1 | |
IBM Connections | =4.0.0.0 | |
IBM Connections | =4.5.0.0 | |
IBM Connections | =5.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-7459 is medium, with a severity score of 5.4.
CVE-2015-7459 affects IBM Connections versions 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4.
CVE-2015-7459 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, leading to potential cross-site scripting (XSS) attacks.
The CWE ID for CVE-2015-7459 is 79.
To fix CVE-2015-7459, it is recommended to apply the necessary updates or patches provided by IBM Connections.