IBM Security Bulletin: IBM Content Navigator affected by dojox/form/resources/*.swf and dojox/av/resources/*.swf XSS vulnerability (CVE-2014-8917)

The dojox/form/resources/fileuploader.swf, dojox/form/resources/uploader.swf, dojox/av/resources/audio.swf and dojox/av/resources/video.swf files exhibit an XSS vulnerability. IBM Content Navigator uses the IBM Dojo Toolkit and might be subject to XSS. ...

from IBM Product Security Incident Response Team http://ift.tt/1NDEj3u