First published: Mon Mar 12 2018(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Curam Social Program Management | >=6.0.4.0<=6.0.4.6 | |
IBM Curam Social Program Management | >=6.0.5.0<=6.0.5.9 | |
IBM Curam Social Program Management | =6.0-sp1 | |
IBM Curam Social Program Management | =6.0-sp2 | |
IBM Curam Social Program Management | =6.0.0 | |
IBM Curam Social Program Management | =6.1.0.0 | |
IBM Curam Social Program Management | =6.1.0.1 | |
IBM Curam Social Program Management | =6.1.1.0 | |
IBM Curam Social Program Management | =6.1.1.1 | |
IBM Care Management | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0261 is medium with a CVSSv3 score of 5.4.
IBM Curam Social Program Management versions 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1 are affected by CVE-2016-0261.
CVE-2016-0261 is a Cross-Site Scripting (XSS) vulnerability.
Remote attackers can exploit CVE-2016-0261 by injecting arbitrary web scripts.
Yes, fixes are available for CVE-2016-0261. Please refer to the official IBM support document for more information.