CVE-2016-0282: XSS
Published Nov 24, 2016
·Updated
Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS.
Affected Software
20 affected components
IBM Lotus iNotes=8.5.0.0
IBM Lotus iNotes=8.5.0.1
IBM Lotus iNotes=8.5.1.0
IBM Lotus iNotes=8.5.1.1
IBM Lotus iNotes=8.5.1.2
IBM Lotus iNotes=8.5.1.3
IBM Lotus iNotes=8.5.1.4
IBM Lotus iNotes=8.5.1.5
IBM Lotus iNotes=8.5.2.0
IBM Lotus iNotes=8.5.2.1
IBM Lotus iNotes=8.5.2.2
IBM Lotus iNotes=8.5.2.3
IBM Lotus iNotes=8.5.2.4
IBM Lotus iNotes=8.5.3.0
IBM Lotus iNotes=8.5.3.1
IBM Lotus iNotes=8.5.3.2
IBM Lotus iNotes=8.5.3.3
IBM Lotus iNotes=8.5.3.4
IBM Lotus iNotes=8.5.3.5
IBM Lotus iNotes=8.5.3.6
Event History
Nov 24, 2016
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0282?
CVE-2016-0282 has a medium severity level as it allows remote authenticated users to exploit XSS vulnerabilities.
2
How do I fix CVE-2016-0282?
To fix CVE-2016-0282, upgrade IBM Lotus iNotes to version 8.5.3 FP6 IF2 or later.
3
What software versions are affected by CVE-2016-0282?
CVE-2016-0282 affects IBM Lotus iNotes versions 8.5.0.0 through 8.5.3.5.
4
Who is impacted by the CVE-2016-0282 vulnerability?
Remote authenticated users of the affected versions of IBM iNotes are at risk due to CVE-2016-0282.
5
What type of vulnerability is CVE-2016-0282?
CVE-2016-0282 is classified as a cross-site scripting (XSS) vulnerability.