First published: Sat Oct 22 2016(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =8.2 | |
IBM InfoSphere Guardium z/OS | =9.0 | |
IBM InfoSphere Guardium z/OS | =9.1 | |
IBM InfoSphere Guardium z/OS | =9.5 | |
IBM InfoSphere Guardium z/OS | =10.0 | |
IBM InfoSphere Guardium z/OS | =10.1 | |
IBM InfoSphere Guardium z/OS | =10.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0246 is considered high due to the potential for remote code execution via cross-site scripting.
To fix CVE-2016-0246, apply the recommended patches or updates provided by IBM for affected versions of IBM Security Guardium.
CVE-2016-0246 affects IBM Security Guardium versions 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100.
Yes, CVE-2016-0246 can be exploited by injecting arbitrary web scripts or HTML through a crafted URL.
CVE-2016-0246 can lead to unauthorized access and data exposure, posing a significant risk to users of the affected software.