IBM Active Content Filtering in IBM Connections Mail is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
CVE(s): CVE-2016-0243
Affected product(s) and affected version(s):
IBM Connections Mail (for IBM Connections 5.5) – 1.7
IBM Connections Mail (for IBM Connections 5.0) – 1.6
IBM Connections Mail (for IBM Connections 4.5) – 1.3
IBM Connections Mail (for IBM Connections 4.0) – 1.0, 1.0 Fix Pack 1
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dvmaHq
X-Force Database: http://ift.tt/2b1mZH9
from IBM Product Security Incident Response Team http://ift.tt/2dvk62x
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.