First published: Mon Aug 08 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Publishing Engine | =2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2912 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2016-2912, upgrade IBM Rational Publishing Engine to version 2.0.1 with ifix002 or later.
CVE-2016-2912 affects remote authenticated users of IBM Rational Publishing Engine version 2.0.1 before ifix002.
CVE-2016-2912 can facilitate cross-site scripting (XSS) attacks that allow attackers to inject arbitrary web scripts or HTML.
CVE-2016-2912 can be exploited easily by sending crafted URLs to authenticated users.