CVE-2016-0261

Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
ibmcuram_social_program_management
6.0.4.0 ≤
𝑥
≤ 6.0.4.6
ibmcuram_social_program_management
6.0.5.0 ≤
𝑥
≤ 6.0.5.9
ibmcuram_social_program_management
6.0:sp1
ibmcuram_social_program_management
6.0:sp2
ibmcuram_social_program_management
6.0.0
ibmcuram_social_program_management
6.1.0.0
ibmcuram_social_program_management
6.1.0.1
ibmcuram_social_program_management
6.1.1.0
ibmcuram_social_program_management
6.1.1.1
ibmcare_management
6.0
𝑥
= Vulnerable software versions