Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1LO88449 | Not Applicable |
http://www-01.ibm.com/support/docview.wss?uid=swg1LO88451 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg21988726 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/92471 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2016-09-01T01:00:00
Updated: 2016-11-25T19:57:01
Reserved: 2015-12-08T00:00:00
Link: CVE-2016-0370
JSON object: View
NVD Information
Status : Modified
Published: 2016-09-01T01:59:02.193
Modified: 2016-11-28T19:53:20.900
Link: CVE-2016-0370
JSON object: View
Redhat Information
No data.
CWE