CVE-2016-0295: XSS
Published Feb 28, 2018
·Updated
Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363.
Affected Software
4 affected components
IBM BigFix Platform>=9.5<9.5.2
IBM BigFix Platform=9.0
IBM BigFix Platform=9.1
IBM BigFix Platform=9.2
Event History
Feb 28, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0295?
CVE-2016-0295 is classified as a medium severity cross-site request forgery (CSRF) vulnerability.
2
How do I fix CVE-2016-0295?
To fix CVE-2016-0295, upgrade IBM BigFix Platform to version 9.5.2 or later.
3
What versions of IBM BigFix Platform are affected by CVE-2016-0295?
IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5 before 9.5.2 are affected by CVE-2016-0295.
4
What type of attack does CVE-2016-0295 enable?
CVE-2016-0295 allows remote attackers to hijack the authentication of users via CSRF attacks.
5
What is the consequence of exploiting CVE-2016-0295?
Exploitation of CVE-2016-0295 can lead to the insertion of XSS sequences into requests.