CVE-2016-0293: XSS
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0293?
CVE-2016-0293 has a high severity level due to its potential for remote code execution through cross-site scripting.
How do I fix CVE-2016-0293?
To fix CVE-2016-0293, upgrade IBM BigFix Platform to version 9.1.8 or higher for 9.x and 9.2.8 or higher for 9.2.x.
What software versions are affected by CVE-2016-0293?
CVE-2016-0293 affects IBM BigFix Platform versions 9.0.5 to 9.0.8 and 9.1.3 to 9.1.7, as well as 9.2.0 to 9.2.7.
Can CVE-2016-0293 be exploited remotely?
Yes, CVE-2016-0293 can be exploited remotely, allowing attackers to inject arbitrary scripts.
Is a patch available for CVE-2016-0293?
Yes, a patch is available in IBM BigFix Platform versions 9.1.8 and 9.2.8 or later.