First published: Wed Feb 01 2017(Updated: )
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere DataStage | =8.7 | |
IBM InfoSphere DataStage | =9.1 | |
IBM InfoSphere DataStage | =11.3 | |
IBM InfoSphere DataStage | =11.5 | |
IBM InfoSphere Information Analyzer | =8.7 | |
IBM InfoSphere Information Analyzer | =9.1 | |
IBM InfoSphere Information Analyzer | =11.3 | |
IBM InfoSphere Information Analyzer | =11.5 | |
IBM InfoSphere Information Server | =11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8999 is classified as a medium severity vulnerability due to the potential for CSS injection.
To fix CVE-2016-8999, ensure that all affected IBM InfoSphere DataStage and Information Server versions are updated to the latest patches provided by IBM.
CVE-2016-8999 affects IBM InfoSphere DataStage versions 8.7, 9.1, 11.3, and 11.5, as well as IBM InfoSphere Information Server versions 8.7, 9.1, 11.3, and 11.5.
The impact of CVE-2016-8999 includes the possibility for attackers to exploit the vulnerability and inject malicious CSS into the affected applications.
Yes, CVE-2016-8999 is related to web security as it involves a vulnerability that allows for potential CSS injection, which can affect web page rendering.