Vulnerability Bulletins

IBM Security Bulletin: IBM Docs dojox/form/resources/*.swf and dojox/av/resources/*.swf XSS vulnerability (CVE-2014-8917 )

   
Affected software IBM
 
IBM Dojo Toolkit is vulnerable to cross-site scripting, caused by improper validation of user-supplied input which affects IBM Docs. CVE(s): CVE-2014-8917 Affected product(s) and affected version(s): IBM Docs 1.0.6 and earlier Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg21694805 X-Force Database: http://xforce.iss.net/xforce/xfdb/99303

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_docs_dojox_form_resources_swf_and_dojox_av_resources_swf_xss_vulnerability_cve_2014_8917?lang=en_us