CVE-2016-0336: XSS
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-0336?
CVE-2016-0336 is a Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001.
How does CVE-2016-0336 affect IBM Security Identity Manager?
CVE-2016-0336 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in IBM Security Identity Manager.
What is the severity of CVE-2016-0336?
CVE-2016-0336 has a severity rating of 5.4 (Medium).
What is the CWE ID for CVE-2016-0336?
The CWE ID for CVE-2016-0336 is 79.
How can I fix the XSS vulnerability in IBM Security Identity Manager?
To fix the XSS vulnerability, update IBM Security Identity Manager to version 7.0.1-ISS-SIM-FP0001 or later.