Vulnerability Bulletins

IBM Security Bulletin: IBM InfoSphere Information Server is vulnerable to Cross-Site Scripting (XSS) (CVE-2016-0280)

   
Affected software IBM
 
IBM InfoSphere Information Server Framework, Information Server Governance Catalog and Information Server Business Glossary are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-infosphere-information-server-is-vulnerable-to-cross-site-scripting-xss-cve-2016-0280/