First published: Wed Feb 01 2017(Updated: )
IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM TRIRIGA Application Platform | =3.3.0.0 | |
IBM TRIRIGA Application Platform | =3.3.0.1 | |
IBM TRIRIGA Application Platform | =3.3.0.2 | |
IBM TRIRIGA Application Platform | =3.3.1.0 | |
IBM TRIRIGA Application Platform | =3.3.1.1 | |
IBM TRIRIGA Application Platform | =3.3.1.2 | |
IBM TRIRIGA Application Platform | =3.3.1.3 | |
IBM TRIRIGA Application Platform | =3.3.2.0 | |
IBM TRIRIGA Application Platform | =3.3.2.1 | |
IBM TRIRIGA Application Platform | =3.3.2.2 | |
IBM TRIRIGA Application Platform | =3.3.2.3 | |
IBM TRIRIGA Application Platform | =3.3.2.4 | |
IBM TRIRIGA Application Platform | =3.3.2.5 | |
IBM TRIRIGA Application Platform | =3.4.0.0 | |
IBM TRIRIGA Application Platform | =3.4.0.1 | |
IBM TRIRIGA Application Platform | =3.4.1.0 | |
IBM TRIRIGA Application Platform | =3.4.1.1 | |
IBM TRIRIGA Application Platform | =3.4.1.2 | |
IBM TRIRIGA Application Platform | =3.4.1.3 | |
IBM TRIRIGA Application Platform | =3.4.2.0 | |
IBM TRIRIGA Application Platform | =3.4.2.1 | |
IBM TRIRIGA Application Platform | =3.4.2.2 | |
IBM TRIRIGA Application Platform | =3.4.2.3 | |
IBM TRIRIGA Application Platform | =3.4.2.4 | |
IBM TRIRIGA Application Platform | =3.5.0.0 | |
IBM TRIRIGA Application Platform | =3.5.0.1 | |
IBM TRIRIGA Application Platform | =3.5.1.0 | |
IBM TRIRIGA Application Platform | =3.5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6000 is classified as a medium severity vulnerability due to its potential to lead to credential disclosure.
To fix CVE-2016-6000, update the IBM TRIRIGA Application Platform to the latest patched version provided by IBM.
CVE-2016-6000 affects multiple versions of the IBM TRIRIGA Application Platform, including versions 3.3.0.0 through 3.5.1.1.
CVE-2016-6000 enables cross-site scripting (XSS) attacks by allowing arbitrary JavaScript code to be embedded in the web UI.
Users of the affected versions of the IBM TRIRIGA Application Platform are at risk of having their session credentials disclosed.