An Apache Struts vulnerability was addressed by IBM Social Media Analytics 1.3.0 IF18.
An upgrade to Apache Struts version 2.3.28.1 was performed.
CVE-ID:CVE-2016-4003
Description: Apache Struts is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the URLDecoder implementation. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base Score:** **6.1
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/111514 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
IBM Social Media Analytics 1.3
The recommended solution is to apply the following interim fix:
IBM Social Media Analytics 1.3.0 IF18
For users of IBM Social Media Analytics 1.2 IBM recommends upgrading to IBM Social Media Analytics 1.3.
IBM recommends that you review your entire environment to identify vulnerable releases of the open-source Apache Struts and take appropriate mitigation and remediation actions.
None known. Apply Social Media Analytics 1.3.0 IF18 interim fix.