IBM Security Bulletin: Multiple vulnerabilities in IBM Tealeaf Customer Experience portal

The IBM Tealeaf Customer Experience web portal is vulnerable to cross-site scripting and redirect attacks and does not manage portal passwords as documented.

CVE(s): CVE-2016-5975, CVE-2016-5976, CVE-2016-5977, CVE-2016-5978, CVE-2016-5996, CVE-2016-5997

Affected product(s) and affected version(s):

IBM Tealeaf Customer Experience 8.0-9.0.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cABvnF
X-Force Database: http://ift.tt/2cgTxxV
X-Force Database: http://ift.tt/2cABjFc
X-Force Database: http://ift.tt/2cgSNJi
X-Force Database: http://ift.tt/2cAB7pn
X-Force Database: http://ift.tt/2cgTqm9
X-Force Database: http://ift.tt/2cACi85



from IBM Product Security Incident Response Team http://ift.tt/2cgUZQQ