CVE-2016-3049: XSS
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3049?
CVE-2016-3049 is considered a medium severity vulnerability due to the potential for HTML injection attacks.
How does CVE-2016-3049 affect IBM OpenPages GRC Platform?
CVE-2016-3049 allows remote attackers to inject malicious HTML code that gets executed in the victim's browser.
Which versions of IBM OpenPages GRC Platform are affected by CVE-2016-3049?
CVE-2016-3049 affects IBM OpenPages GRC Platform versions 7.1, 7.2, and 7.3.
How do I fix CVE-2016-3049?
To fix CVE-2016-3049, update your IBM OpenPages GRC Platform to a version that includes the security patch provided by IBM.
What should I do if I am vulnerable to CVE-2016-3049?
If vulnerable to CVE-2016-3049, it is advised to apply the security update immediately and review your web application for potential exploitation.