CVE-2016-5882: XSS
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5882?
CVE-2016-5882 is considered a medium severity vulnerability due to the potential for credential disclosure.
How do I fix CVE-2016-5882?
To fix CVE-2016-5882, update IBM iNotes or IBM Domino to a version that includes patches for this vulnerability.
What impact does CVE-2016-5882 have on users?
CVE-2016-5882 allows attackers to exploit cross-site scripting, which could lead to unauthorized actions performed in the context of a trusted session.
Which versions of IBM iNotes are affected by CVE-2016-5882?
Versions 8.5.1.0 through 9.0.1.6 of IBM iNotes are affected by CVE-2016-5882.
Can CVE-2016-5882 be exploited remotely?
Yes, CVE-2016-5882 can be exploited remotely if an attacker can craft a malicious payload that targets the iNotes web interface.