CVE-2016-0283: XSS
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0283?
CVE-2016-0283 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-0283?
To fix CVE-2016-0283, update your IBM WebSphere Application Server Liberty Profile to version 8.5.5.9 or later.
Who can exploit CVE-2016-0283?
Remote attackers can exploit CVE-2016-0283 by injecting arbitrary web scripts or HTML through a crafted URL.
What versions of IBM WebSphere Application Server are affected by CVE-2016-0283?
CVE-2016-0283 affects IBM WebSphere Application Server Liberty Profile versions 8.5.5.0 to 8.5.5.8.
What is the nature of the vulnerability in CVE-2016-0283?
CVE-2016-0283 is a cross-site scripting (XSS) vulnerability that allows for the injection of malicious scripts into web applications.