CVE-2016-5883: XSS
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997010.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5883?
CVE-2016-5883 is classified as a moderate severity vulnerability due to the risk of cross-site scripting attacks.
How do I fix CVE-2016-5883?
To fix CVE-2016-5883, update IBM iNotes to the latest version where the vulnerability has been patched.
What systems are affected by CVE-2016-5883?
CVE-2016-5883 affects various versions of IBM iNotes, including versions 8.5.1.0 to 8.5.3.6 and 9.0.0.0 to 9.0.1.6.
What type of attack does CVE-2016-5883 enable?
CVE-2016-5883 enables cross-site scripting (XSS) attacks which can lead to unauthorized script execution within a user's session.
Can I be targeted by CVE-2016-5883 if I use an updated version of IBM iNotes?
If you are using an updated version of IBM iNotes that addresses CVE-2016-5883, you should be protected from this vulnerability.