IBM Security Bulletin: IBM InfoSphere Master Data Management Server is vulnerable to cross-site scripting Attack (CVE-2016-9715)

Share this post:

IBM InfoSphere Master Data Management is vulnerable to a cross-site scripting Attack and could allow users to embed arbitrary JavaScript code in the Web UI and lead to disclosure of credentials.

CVE(s): CVE-2016-9715

Affected product(s) and affected version(s):

This vulnerability is known to affect the following offerings:

Affected IBM InfoSphere Master Data Management ServerAffected Versions
IBM InfoSphere Master Data Management11.0
IBM InfoSphere Master Data Management11.3
IBM InfoSphere Master Data Management11.4
IBM InfoSphere Master Data Management11.5
IBM InfoSphere Master Data Management11.6

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2v6gpKE
X-Force Database: http://ift.tt/2tJiyrY



from IBM Product Security Incident Response Team http://ift.tt/2v6woIo