Cross-Site Scripting Vulnerabilities in IBM Lotus Protector for Mail Security
CVE-2016-2991

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 December 2016

Summary

IBM Lotus Protector for Mail Security versions 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 are vulnerable to multiple cross-site scripting (XSS) issues. Remote authenticated users may exploit these vulnerabilities to inject arbitrary web scripts or HTML, potentially leading to unauthorized actions on behalf of the user. Effective measures should be implemented to safeguard against these vulnerabilities.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.