First published: Thu Sep 01 2016(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Forms Experience Builder | =8.5.0.0 | |
IBM Forms Experience Builder | =8.5.1.0 | |
IBM Forms Experience Builder | =8.5.1.1 | |
IBM Forms Experience Builder | =8.6.0.0 | |
IBM Forms Experience Builder | =8.6.1 | |
IBM Forms Experience Builder | =8.6.1.1 | |
IBM Forms Experience Builder | =8.6.2 | |
IBM Forms Experience Builder | =8.6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0370 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2016-0370, upgrade IBM Forms Experience Builder to version 8.6.3 or later.
CVE-2016-0370 affects users of IBM Forms Experience Builder versions 8.5.x and 8.6.x prior to 8.6.3.
CVE-2016-0370 enables remote authenticated users to perform cross-site scripting (XSS) attacks.
CVE-2016-0370 impacts various versions of IBM Forms Experience Builder, specifically 8.5.0.0 to 8.6.2.1.