Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Cúram Social Program Management is Vulnerable to Reflected Cross-Site Scripting (CVE-2015-7402)

   
Software afectado IBM
 
IBM Cúram Social Program Management is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. An already authenticated attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victims Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victims cookie-based authentication credentials. CVE(s): CVE-2015-7402 Affected

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_c%25c3%25baram_social_program_management_is_vulnerable_to_reflected_cross_site_scripting_cve_2015_7402?lang=en_us