Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in Apache Cordova affects IBM MobileFirst Platform Foundation (CVE-2015-5256)

   
Affected software IBM
 
An Apache Cordova Vulnerability for improper application of whitelist restrictions on Android was addressed by IBM MobileFirst Platform Foundation. Android applications created using Apache Cordova that use a remote server contain a vulnerability where whitelist restrictions are not properly applied. Improperly crafted URIs could be used to circumvent the whitelist, allowing for the execution of non-whitelisted JavaScript. CVE(s): CVE-2015-5256Affected product(s) and affected version(s):IBM

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_apache_cordova_affects_ibm_mobilefirst_platform_foundation_cve_2015_5256?lang=en_us