CVE-2016-9696: XSS
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM Reference #: 1999960.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9696?
The severity of CVE-2016-9696 is considered high due to the potential for remote HTML injection leading to the execution of malicious scripts.
How do I fix CVE-2016-9696?
To fix CVE-2016-9696, it is recommended to update IBM Rhapsody Design Manager to the latest version provided by IBM.
What versions are affected by CVE-2016-9696?
CVE-2016-9696 affects versions 4.0 to 6.0.2 of IBM Rhapsody Design Manager.
Can CVE-2016-9696 be exploited remotely?
Yes, CVE-2016-9696 can be exploited remotely by injecting malicious HTML code into the application.
What are the potential consequences of CVE-2016-9696?
The potential consequences of CVE-2016-9696 include unauthorized execution of scripts and possible theft of sensitive information from users.