CVE-2016-0209: XSS
Published Jan 27, 2016
·Updated
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF09 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
IBM WebSphere Portal=8.5.0.0
Event History
Jan 27, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0209?
CVE-2016-0209 has a medium severity rating due to its potential impact on user data and application security.
2
How do I fix CVE-2016-0209?
To fix CVE-2016-0209, apply the latest security update or patch provided by IBM for WebSphere Portal version 8.5.0 before CF09.
3
What types of attacks are possible with CVE-2016-0209?
CVE-2016-0209 allows for cross-site scripting attacks, which can lead to malicious code execution in the context of a user's browser.
4
Which versions of IBM WebSphere Portal are affected by CVE-2016-0209?
CVE-2016-0209 affects IBM WebSphere Portal version 8.5.0.0 prior to fix pack CF09.
5
Who can exploit CVE-2016-0209?
Remote attackers can exploit CVE-2016-0209 by injecting arbitrary web scripts or HTML via unspecified vectors.