First published: Mon Sep 26 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-5978.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tealeaf CX | <=8.7 | |
IBM Tealeaf CX | =8.8 | |
IBM Tealeaf CX | =9.0.0 | |
IBM Tealeaf CX | =9.0.1 | |
IBM Tealeaf CX | =9.0.1a | |
IBM Tealeaf CX | =9.0.2 | |
IBM Tealeaf CX | =9.0.2a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5975 is classified as a Cross-site Scripting (XSS) vulnerability, which can potentially allow attackers to execute malicious scripts in the context of a user's browser.
To fix CVE-2016-5975, upgrade to IBM Tealeaf Customer Experience versions 8.7.1.8847 FP10, 8.8.0.9049 FP9, or any of the later specified versions.
CVE-2016-5975 affects IBM Tealeaf Customer Experience versions up to 8.7, version 8.8, 9.0.0, 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224.
CVE-2016-5975 is a Cross-site Scripting (XSS) vulnerability that affects the web portal of IBM Tealeaf Customer Experience.
Yes, if you are using the affected versions of IBM Tealeaf Customer Experience, CVE-2016-5975 can be exploited to compromise the security of your web applications.