MEDIUM
IBM iNotes is vulnerable to cross-site scripting
Published Feb 1, 2017
6.1
MEDIUMCVSS 3.0
EPSS 0.96%
Description
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected products
-
- Version 8.0StatusaffectedConstraints-
- Version 8.0.1StatusaffectedConstraints-
- Version 8.0.2StatusaffectedConstraints-
- Version 8.5StatusaffectedConstraints-
- Version 8.5.0.1StatusaffectedConstraints-
- Version 8.5.1StatusaffectedConstraints-
- Version 8.5.1.1StatusaffectedConstraints-
- Version 8.5.1.4StatusaffectedConstraints-
- Version 8.5.1.5StatusaffectedConstraints-
- Version 8.5.2StatusaffectedConstraints-
- Version 8.5.2.4StatusaffectedConstraints-
- Version 8.5.3StatusaffectedConstraints-
- Version 8.5.3.5StatusaffectedConstraints-
- Version 8.5.3.6StatusaffectedConstraints-
- Version 9.0StatusaffectedConstraints-
- Version 9.0.1StatusaffectedConstraints-
- Version 9.0.1.1StatusaffectedConstraints-
- Version 9.0.1.2StatusaffectedConstraints-
- Version 9.0.1.3StatusaffectedConstraints-
- Version 9.0.1.4StatusaffectedConstraints-
- Version 9.0.1.5StatusaffectedConstraints-
- Version 9.0.1.6StatusaffectedConstraints-
- Version 9.0.1.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM Corporation | Domino | n/a |
|
OR
- 8.5.1.0
- 8.5.1.1
- 8.5.1.2
- 8.5.1.3
- 8.5.1.4
- 8.5.1.5
- 8.5.2.0
- 8.5.2.1
- 8.5.2.2
- 8.5.2.3
- 8.5.2.4
- 8.5.3.0
- 8.5.3.1
- 8.5.3.2
- 8.5.3.3
- 8.5.3.4
- 8.5.3.5
- 8.5.3.6
- 9.0.0.0
- 9.0.1.0
- 9.0.1.1
- 9.0.1.2
- 9.0.1.3
- 9.0.1.4
- 9.0.1.5
- 9.0.1.6
- 8.5.1.0
- 8.5.1.1
- 8.5.1.2
- 8.5.1.3
- 8.5.1.4
- 8.5.1.5
- 8.5.2.0
- 8.5.2.1
- 8.5.2.2
- 8.5.2.3
- 8.5.3.0
- 8.5.3.1
- 8.5.3.2
- 8.5.3.3
- 8.5.3.4
- 8.5.3.5
- 8.5.3.6
- 9.0.0.0
- 9.0.1.0
- 9.0.1.1
- 9.0.1.2
- 9.0.1.3
- 9.0.1.4
- 9.0.1.5
- 9.0.1.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.ibm.com/support/docview.wss?uid=swg21992835 x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/94604 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037383 vdb-entryx_refsource_SECTRACK
| Link | Providers | Tags |
|---|---|---|
| http://www.ibm.com/support/docview.wss?uid=swg21992835 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.securityfocus.com/bid/94604 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1037383 | vdb-entryx_refsource_SECTRACK |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Feb 1, 2017
Updated Aug 6, 2024
Reserved Jun 29, 2016
Link CVE-2016-5882
CISA Vulnrichment
Updated n/a