PT-2016-5343 · Ibm · Ibm Filenet Workplace

Roshan Thomas

·

Published

2016-08-08

·

Updated

2016-11-28

·

CVE-2016-3054

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM FileNet Workplace version 4.0.2
Description A cross-site scripting (XSS) issue allows remote authenticated users to inject arbitrary web script or HTML by uploading a file. This occurs because the software does not properly validate or sanitize user-inputted data, specifically files uploaded by users.
Recommendations For IBM FileNet Workplace version 4.0.2, update the software to a version that includes fixes for this issue, as no specific workaround is provided for this version.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3054

Affected Products

Ibm Filenet Workplace