Security Bulletin
Summary
Security Bulletin: IBM Resilient - Cross Site Scripting Vulnerability (CVE-2016-6062)
Vulnerability Details
Security Bulletin
Summary
IBM Resilient is vulnerable to cross-site scripting.
Vulnerability Details
CVEID: CVE-2016-6062
DESCRIPTION: IBM Resilient is vulnerable to cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS Base Score: 6.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/117235 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Affected Products and Version
All versions of IBM Resilient prior to v26.3 are vulnerable to this defect.
Remediation/Fixes
On-premises users of IBM Resilient are urged to upgrade to version 26.3 of the product. Customers may obtain information about this release at the IBMResilient Success Hub:
Workarounds and Mitigations
There are no known workarounds for this vul
Get Notified about Future Security Bulletins
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
19 April 2021
UID
ibm11162774