Cross-Site Scripting Vulnerability in IBM Emptoris Sourcing
CVE-2016-8948
What is CVE-2016-8948?
IBM Emptoris Sourcing versions 9.5.x through 10.1.x are susceptible to a cross-site scripting (XSS) vulnerability. This flaw enables attackers to inject arbitrary JavaScript code into the Web UI, which can manipulate the application's functionality. Such alterations could result in the disclosure of sensitive information, including user credentials, within a trusted session. Users of affected versions are advised to take measures to mitigate potential risks by applying security best practices and checking for patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Emptoris Sourcing 9.5
Emptoris Sourcing 10.0.0
Emptoris Sourcing 10.0.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved