IBM Security Bulletin: Multiple vulnerabilities in IBM Tealeaf Customer Experience portal
The IBM Tealeaf Customer Experience web portal is vulnerable to cross-site scripting and redirect attacks and does not manage portal passwords as documented.
CVE(s): CVE-2016-5975, CVE-2016-5976, CVE-2016-5977, CVE-2016-5978, CVE-2016-5996, CVE-2016-5997
Affected product(s) and affected version(s):
IBM Tealeaf Customer Experience 8.0-9.0.2
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cABvnF
X-Force Database: http://ift.tt/2cgTxxV
X-Force Database: http://ift.tt/2cABjFc
X-Force Database: http://ift.tt/2cgSNJi
X-Force Database: http://ift.tt/2cAB7pn
X-Force Database: http://ift.tt/2cgTqm9
X-Force Database: http://ift.tt/2cACi85
from IBM Product Security Incident Response Team http://ift.tt/2cgUZQQ