VulnerabilityModified
CVE-2016-0370
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.
LOW 2.7EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.
- CVSS 3.0
- 2.7 LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/forms experience builder
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO88449Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO88451Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21988726Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92471
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO88449Not Applicable
- http://www-01.ibm.com/support/docview.wss?uid=swg1LO88451Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21988726Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92471
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.