Lucene search

K
ibmIBM9CD97D98DE6C82134DEE5214E2D5F5D1AEAF965F2A97DAAF01EFCEB2D2AE7B57
HistoryJun 17, 2018 - 12:10 p.m.

Security Bulletin: IBM Content Navigator is potentially vulnerable to cross-site scripting, caused by improper validation of user-supplied input (CVE-2015-1888)

2018-06-1712:10:35
www.ibm.com
6

0.001 Low

EPSS

Percentile

27.4%

Summary

IBM Content Navigator is potentially vulnerable to cross-site scripting, caused by improper validation of user-supplied input.

Vulnerability Details

CVEID: CVE-2015-1888
IBM Content Navigator is vulnerable to cross-site scripting. The vulnerability is caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/101262 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

Affected Products and Versions

IBM Content Navigator 2.0.3

IBM Content Navigator is a component that is available to customers in these products (and the products that contain them):

  • IBM Content Manager
  • IBM FileNet Content Manager
  • IBM Content Foundation
  • IBM Content Manager OnDemand

Remediation/Fixes

Version 2.0.2 Apply fix pack 2.0.2-ICN-FP007, or higher

Version 2.0.3 Apply fix pack 2.0.3-ICN-FP003, or higher

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

27.4%

Related for 9CD97D98DE6C82134DEE5214E2D5F5D1AEAF965F2A97DAAF01EFCEB2D2AE7B57