IBM Security Bulletin: Lotus Protector for Mail Security affected by Cross Site Scripting (CVE-2016-2991)

Cross site scripting vulnerabilities were found in various end-use facing weblinks for Lotus Protector for Mail Security.

CVE(s): CVE-2016-2991

Affected product(s) and affected version(s):

Lotus Protector for Mail Security v2.8.0.0 – 2.8.1.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2bguYiN
X-Force Database: http://ift.tt/2b5AR5S



from IBM Product Security Incident Response Team http://ift.tt/2bguU2B