First published: Mon Jul 31 2017(Updated: )
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119728.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Master Data Management Collaborative Server | =11.0 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.3 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.4 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.5 | |
IBM InfoSphere Master Data Management Collaborative Server | =11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9715 is classified as a cross-site scripting vulnerability which can lead to severe security risks including credential disclosure.
To fix CVE-2016-9715, it is recommended to update the IBM InfoSphere Master Data Management Server to the latest patched version provided by IBM.
CVE-2016-9715 affects IBM InfoSphere Master Data Management Server versions 11.0, 11.3, 11.4, 11.5, and 11.6.
Attackers exploiting CVE-2016-9715 can embed arbitrary JavaScript code in the Web UI, potentially altering functionality and stealing user credentials.
There is no specific workaround for CVE-2016-9715; the best approach is to apply the latest security updates from IBM.