First published: Tue Mar 20 2018(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108356.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | <=3.0.1.1 | |
IBM Connections | =4.0.0.0 | |
IBM Connections | =4.5.0.0 | |
IBM Connections | =5.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2015-7460.
The severity of CVE-2015-7460 is medium with a CVSS score of 5.4.
The affected software for CVE-2015-7460 is IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4.
Remote attackers can inject arbitrary web script or HTML using unspecified vectors to exploit CVE-2015-7460.
Yes, there is a patch available for CVE-2015-7460. Please refer to the IBM support documentation for more information and to obtain the patch.