IBM Security Bulletin: A Cross-site scripting vulnerability in IBM Websphere Application Server, affects IBM Tivoli Netcool Configuration Manager (ITNCM) (CVE-2016-8934)

There is a potential Cross-site scripting security vulnerability in IBM WebSphere Application Server, that is used by IBM Tivoli Netcool Configuration Manager (ITNCM).

CVE(s): CVE-2016-8934

Affected product(s) and affected version(s):

This vulnerability affects the following versions and releases of IBM WebSphere Application Server

·Version 8.5.5 Full Profile and Liberty
·Version 7.0

Included in the following releases:

ITNCM 6.4.2.0 – 6.4.2.3
ITNCM 6.4.1.0 – 6.4.1.4

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2sYcVq6
X-Force Database: http://ift.tt/2ilu2PU

The post IBM Security Bulletin: A Cross-site scripting vulnerability in IBM Websphere Application Server, affects IBM Tivoli Netcool Configuration Manager (ITNCM) (CVE-2016-8934) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2sY79Vt