CVE-2016-5944: XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5944?
CVE-2016-5944 has a medium severity level due to its cross-site scripting (XSS) capabilities that can compromise user data.
How do I fix CVE-2016-5944?
To fix CVE-2016-5944, upgrade to IBM Spectrum Control version 5.2.11 or later.
Who is affected by CVE-2016-5944?
CVE-2016-5944 affects users of IBM Spectrum Control versions 5.2.0 to 5.2.10 and associated Tivoli Storage Productivity Center versions.
Can CVE-2016-5944 be exploited remotely?
Yes, CVE-2016-5944 can be exploited remotely by authenticated users to inject arbitrary web scripts.
What type of vulnerability is CVE-2016-5944 classified as?
CVE-2016-5944 is classified as a cross-site scripting (XSS) vulnerability.