Vulnerability Bulletins |
IBM Security Bulletin: IBM WebSphere MQ XR WebSockets listener is vulnerable to reflected cross-site scripting (CVE-2015-0176) |
|
| Affected software | IBM |
|
MQ XR WebSockets Listener does not properly sanitize URI in error response which could be used in a reflected cross-site scripting attack. CVE(s): CVE-2015-0176 Affected product(s) and affected version(s): IBM WebSphere MQ 8.0 Maintenance level 8.0.0.1 and earlier Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21699549 X-Force Database: More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_websphere_mq_xr_websockets_listener_is_vulnerable_to_reflected_cross_site_scripting_cve_2015_0176?lang=en_us |
|






