Lucene search

K
ibmIBMAC035917BBBBB290FECDCB4EAA5CB6233070460F3DE2202B965DD57EFCA424A3
HistoryJun 17, 2018 - 3:20 p.m.

Security Bulletin: IBM TRIRIGA Application Platform Cross Site Scripting Vulnerability (CVE-2016-0344)

2018-06-1715:20:41
www.ibm.com
7

0.001 Low

EPSS

Percentile

25.7%

Summary

The IBM TRIRIGA Application Platform is vulnerable to a cross site scripting attack within My Reports.

Vulnerability Details

CVEID:__ CVE-2016-0344__

CVSS Base Score: 5.4
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/111785&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected Products and Versions
The following IBM TRIRIGA Application Platform versions are affected.
ยท IBM TRIRIGA Application Platform 3.5.
ยท IBM TRIRIGA Application Platform 3.4.
ยท IBM TRIRIGA Application Platform 3.3.

Remediation/Fixes

This vulnerability is resolved in the IBM TRIRIGA Application Platform 3.5.0.1, 3.4.2.3, and 3.3.2.6 fix packs. The IBM TRIRIGA Application Platform 3.5.0.1 and 3.4.2.3 fix packs are available on Fix Central. The 3.3.2.6 fix pack is available as a limited available fix pack, and can be requested through customer support.

For any IBM TRIRIGA Application Platform prior to 3.3.2, IBM TRIRIGA recommends upgrading to a fixed, supported IBM TRIRIGA Application platform.

Workarounds and Mitigations

Until you apply the fixes, it may be possible to reduce the risk of a successful attack by restricting access to internal networks, and not allowing external/Internet access to the application.

0.001 Low

EPSS

Percentile

25.7%

Related for AC035917BBBBB290FECDCB4EAA5CB6233070460F3DE2202B965DD57EFCA424A3