First published: Sat Jul 02 2016(Updated: )
Cross-site scripting (XSS) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2883.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM TRIRIGA Application Platform | =3.3.0.0 | |
IBM TRIRIGA Application Platform | =3.3.0.1 | |
IBM TRIRIGA Application Platform | =3.3.1.0 | |
IBM TRIRIGA Application Platform | =3.3.1.1 | |
IBM TRIRIGA Application Platform | =3.3.1.2 | |
IBM TRIRIGA Application Platform | =3.3.2.0 | |
IBM TRIRIGA Application Platform | =3.3.2.1 | |
IBM TRIRIGA Application Platform | =3.3.2.2 | |
IBM TRIRIGA Application Platform | =3.3.2.3 | |
IBM TRIRIGA Application Platform | =3.3.2.4 | |
IBM TRIRIGA Application Platform | =3.3.2.5 | |
IBM TRIRIGA Application Platform | =3.4.0.0 | |
IBM TRIRIGA Application Platform | =3.4.0.1 | |
IBM TRIRIGA Application Platform | =3.4.1.0 | |
IBM TRIRIGA Application Platform | =3.4.1.1 | |
IBM TRIRIGA Application Platform | =3.4.1.2 | |
IBM TRIRIGA Application Platform | =3.4.1.3 | |
IBM TRIRIGA Application Platform | =3.4.2.0 | |
IBM TRIRIGA Application Platform | =3.4.2.1 | |
IBM TRIRIGA Application Platform | =3.4.2.2 | |
IBM TRIRIGA Application Platform | =3.4.2.3 | |
IBM TRIRIGA Application Platform | =3.5.0.0 | |
IBM TRIRIGA Application Platform | =3.5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0387 has been classified as a moderate severity vulnerability due to its ability to enable cross-site scripting attacks.
To fix CVE-2016-0387, upgrade the affected IBM TRIRIGA Application Platform to version 3.3.2.6, 3.4.2.4, or 3.5.0.2 or later.
Remote authenticated users of IBM TRIRIGA Application Platform versions before 3.3.2.6, 3.4.2.4, and 3.5.0.2 are affected by CVE-2016-0387.
CVE-2016-0387 can enable attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Versions 3.3.0.0 through 3.3.2.5, 3.4.0.0 through 3.4.2.3, and 3.5.0.0 through 3.5.0.1 of IBM TRIRIGA Application Platform are vulnerable to CVE-2016-0387.