First published: Mon Feb 15 2016(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager 9.0 | =9.0.0 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.1 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.2 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.3 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.5 | |
IBM Security Access Manager for Web 8.0 | =8.0.1 | |
IBM Security Access Manager for Web 8.0 | =8.0.1.0 | |
IBM Security Access Manager for Web 8.0 | =8.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8531 is classified as a medium severity vulnerability, allowing cross-site scripting attacks.
To fix CVE-2015-8531, upgrade to IBM Security Access Manager for Web 8.0 version 8.0.1.3 IF4 or IBM Security Access Manager 9.0 version 9.0.0.1 IF1 or later.
CVE-2015-8531 is a cross-site scripting (XSS) vulnerability.
CVE-2015-8531 affects IBM Security Access Manager for Web 8.0 versions prior to 8.0.1.3 IF4 and IBM Security Access Manager 9.0 versions before 9.0.0.1 IF1.
CVE-2015-8531 can be exploited by remote attackers who can craft malicious URLs to inject arbitrary web scripts or HTML.