Vulnerability Bulletins |
IBM Security Bulletin: IBM Docs dojox/form/resources/*.swf and dojox/av/resources/*.swf XSS vulnerability (CVE-2014-8917 ) |
|
| Affected software | IBM |
|
IBM Dojo Toolkit is vulnerable to cross-site scripting, caused by improper validation of user-supplied input which affects IBM Docs. CVE(s): CVE-2014-8917 Affected product(s) and affected version(s): IBM Docs 1.0.6 and earlier Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg21694805 X-Force Database: http://xforce.iss.net/xforce/xfdb/99303 More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_docs_dojox_form_resources_swf_and_dojox_av_resources_swf_xss_vulnerability_cve_2014_8917?lang=en_us |
|






