XSS Vulnerability in IBM Domino Web Server Product
CVE-2015-2015

Currently unrated

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
23 August 2015

Summary

A cross-site scripting (XSS) vulnerability exists in the pubnames.ntf (Directory template) of the web server in IBM Domino prior to version 9.0.0. This flaw permits remote attackers to inject arbitrary web scripts or HTML via specially crafted URLs, thereby compromising the web application’s integrity and user security. Exploitation of this vulnerability can lead to unauthorized actions being performed on behalf of users, impacting their data and privacy.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.