First published: Wed Feb 21 2018(Updated: )
Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111785.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM TRIRIGA Application Platform | >=3.3.0.0<3.3.2.6 | |
IBM TRIRIGA Application Platform | >=3.4.0.0<=3.4.2.3 | |
IBM TRIRIGA Application Platform | =3.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0344 is classified as a medium-severity cross-site scripting vulnerability.
To fix CVE-2016-0344, upgrade to IBM TRIRIGA Application Platform version 3.3.2.6, 3.4.2.3, or 3.5.0.1 or later.
CVE-2016-0344 affects IBM TRIRIGA Application Platform versions prior to 3.3.2.6, 3.4.2.3, and 3.5.0.1.
CVE-2016-0344 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2016-0344 can be exploited by remote attackers to inject arbitrary web script or HTML.