CVE-2016-0269: XSS
Published Jul 15, 2016
·Updated
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
16 affected components
IBM BigFix Platform=9.2.0
IBM BigFix Platform=9.2.1
IBM BigFix Platform=9.2.2
IBM BigFix Platform=9.2.3
IBM BigFix Platform=9.2.4
IBM BigFix Platform=9.2.5
IBM BigFix Platform=9.2.6
IBM BigFix Platform=9.0.5
IBM BigFix Platform=9.0.6
IBM BigFix Platform=9.0.7
IBM BigFix Platform=9.0.8
IBM BigFix Platform=9.1.3
IBM BigFix Platform=9.1.4
IBM BigFix Platform=9.1.5
IBM BigFix Platform=9.1.6
IBM BigFix Platform=9.1.7
Event History
Jul 15, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0269?
CVE-2016-0269 has a medium severity rating, as it allows remote authenticated users to execute cross-site scripting attacks.
2
Who is affected by CVE-2016-0269?
CVE-2016-0269 affects IBM BigFix Platform versions 9.x prior to 9.1.8 and 9.2.x prior to 9.2.7.
3
How do I fix CVE-2016-0269?
To fix CVE-2016-0269, upgrade your IBM BigFix Platform to version 9.1.8 or later, or to version 9.2.7 or later.
4
What type of vulnerability is CVE-2016-0269?
CVE-2016-0269 is classified as a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2016-0269?
Attackers exploiting CVE-2016-0269 can inject arbitrary web scripts or HTML into affected IBM BigFix applications.