CVE-2016-8968: XSS
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998515.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8968?
CVE-2016-8968 is considered to be of medium severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-8968?
To fix CVE-2016-8968, ensure that you apply the latest security patches provided by IBM for the affected versions of IBM Collaborative Lifecycle Management.
What versions of IBM Collaborative Lifecycle Management are affected by CVE-2016-8968?
CVE-2016-8968 affects IBM Collaborative Lifecycle Management versions 6.0.0, 6.0.1, and 6.0.2.
What could happen if CVE-2016-8968 is exploited?
If CVE-2016-8968 is exploited, it may allow an attacker to execute arbitrary JavaScript in the user's session, potentially leading to credential theft.
Is there a workaround for CVE-2016-8968?
Currently, there are no documented workarounds for CVE-2016-8968; applying the fix is the recommended approach.