Vulnerability Bulletins

IBM Security Bulletin: IBM Content Navigator affected by dojox/form/resources/*.swf and dojox/av/resources/*.swf XSS vulnerability (CVE-2014-8917)

   
Affected software IBM
 
The dojox/form/resources/fileuploader.swf, dojox/form/resources/uploader.swf, dojox/av/resources/audio.swf and dojox/av/resources/video.swf files exhibit an XSS vulnerability. IBM Content Navigator uses the IBM Dojo Toolkit and might be subject to XSS. CVE(s): CVE-2014-8917 Affected product(s) and affected version(s): IBM Content Navigator 2.0.0, 2.0.1, 2.0.2 and 2.0.3 IBM Content Navigator is a component that is available to customers in these products (and the products that contain

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_content_navigator_affected_by_dojox_form_resources_swf_and_dojox_av_resources_swf_xss_vulnerability_cve_2014_8917?lang=en_us