MEDIUM
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting
Published Aug 3, 2017
6.1
MEDIUMCVSS 3.0
EPSS 0.97%
Description
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126062.
Affected products
-
Affected
- 8.5
- 8.5.1
- 8.5.1.1
- 8.5.1.5
- 8.5.2
- 8.5.2.1
- 8.5.2.4
- 8.5.3
- 8.5.3.1
- 8.5.3.6
- 9.0
- 9.0.1
- 9.0.1.1
- 9.0.1.8
OR
- 8.5.0.0
- 8.5.1.0
- 8.5.1.1
- 8.5.1.5
- 8.5.2.0
- 8.5.2.1
- 8.5.2.4
- 8.5.3.0
- 8.5.3.1
- 8.5.3.6
- 9.0.0.0
- 9.0.1.0
- 9.0.1.1
- 9.0.1.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www.ibm.com/support/docview.wss?uid=swg22003664 x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/100139 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-10343 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/126062 x_refsource_MISCVDB EntryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.ibm.com/support/docview.wss?uid=swg22003664 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.securityfocus.com/bid/100139 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-10343 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/126062 | x_refsource_MISCVDB EntryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Aug 3, 2017
Updated Sep 16, 2024
Reserved Nov 30, 2016
Link CVE-2017-1327
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data