Vulnerability Bulletins |
IBM Security Bulletin: IBM Mobile Foundation, IBM Worklight, and IBM Worklight Foundation are affected by the following Apache Cordova vulnerabilities: CVE-2014-3500, CVE-2014-3501 and CVE-2014-3502 |
|
| Affected software | IBM |
|
Apache Cordova, which is used by these products, is vulnerable to Cross-Application Scripting (XAS) and Data Exfiltration vulnerabilities. A remote attacker might exploit these vulnerabilities to expose sensitive data from the mobile application. CVE(s): CVE-2014-3500, CVE-2014-3501 and CVE-2014-3502 Affected product(s) and affected version(s): IBM Mobile Foundation and IBM Worklight Consumer Edition Versions 5.0.6.0, 5.0.6.1 and 5.0.6.2 IBM Mobile Foundation and IBM Worklight More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_mobile_foundation_ibm_worklight_and_ibm_worklight_foundation_are_affected_by_the_following_apache_cordova_vulnerabilities_cve_2014_3500_cve_2014_3501_and_cve_2014_3502?la |
|






