Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in Apache Cordova Android may affect IBM WebSphere Portal (CVE-2015-5256)

   
Affected software IBM
 
IBM WebSphere Portal provides an integration with IBM MobileFirst. An Apache Cordova Vulnerability (CVE-2015-5256) for improper application of whitelist restrictions on Android was addressed by IBM MobileFirst Platform Foundation. Android applications created using Apache Cordova that use a remote server contain a vulnerability where whitelist restrictions are not properly applied. Improperly crafted URIs could be used to circumvent the whitelist, allowing for the execution of non-whitelisted

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_apache_cordova_android_may_affect_ibm_websphere_portal_cve_2015_5256?lang=en_us