PT-2016-4133 · Ibm · Ibm Bigfix Platform

Published

2016-09-01

·

Updated

2016-11-28

·

CVE-2016-0293

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM BigFix Platform versions 9.0.0 through 9.1.7 IBM BigFix Platform versions 9.2.0 through 9.2.7
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file. This could potentially lead to unauthorized actions on the affected system.
Recommendations For IBM BigFix Platform versions 9.0.0 through 9.1.7, update to version 9.1.8 or later. For IBM BigFix Platform versions 9.2.0 through 9.2.7, update to version 9.2.8 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0293

Affected Products

Ibm Bigfix Platform