CVE-2016-2994: XSS
Published Dec 1, 2016
·Updated
Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
6 affected components
IBM UrbanCode Deploy=6.2.0.0
IBM UrbanCode Deploy=6.2.0.1
IBM UrbanCode Deploy=6.2.0.2
IBM UrbanCode Deploy=6.2.0.201
IBM UrbanCode Deploy=6.2.1
IBM UrbanCode Deploy=6.2.1.1
Event History
Dec 1, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2994?
CVE-2016-2994 has a medium severity rating due to its cross-site scripting (XSS) vulnerability affecting IBM UrbanCode Deploy.
2
How do I fix CVE-2016-2994?
To fix CVE-2016-2994, upgrade to IBM UrbanCode Deploy version 6.2.1.2 or later, which includes necessary patches.
3
Who is affected by CVE-2016-2994?
CVE-2016-2994 affects remote authenticated users of IBM UrbanCode Deploy versions 6.2.0.0 to 6.2.1.1.
4
What type of vulnerability is CVE-2016-2994?
CVE-2016-2994 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2016-2994 allow malicious scripts to be executed?
Yes, CVE-2016-2994 allows remote authenticated users to inject and execute arbitrary web scripts or HTML.