CVE-2016-0336
published 2018-01-12CVE-2016-0336: Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.64%
46.6th percentile
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_identity_manager | — | — |
| ibm | security_identity_manager | — | — |
| ibm | security_identity_manager | — | — |
| ibm | security_identity_manager | — | — |
| ibm | security_identity_manager | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name
bugzilla·2016-11-09·CVSS 6.1
CVE-2016-8639 [MEDIUM] CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name
CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name
Sanket Jagtap of Red Hat reports:
If an organization or location is created with a name containing HTML,
then the administrator-only Settings page will render the HTML as part
of a dropdown menu.
This may permit a stored XSS attack if an organization/location with
HTML in the name is created, then an administrator attempts to change
the default organization/location settings.
Upstream bug:
http://projects.theforeman.org/issues/15037
Upstream patch:
https://github.com/theforeman/foreman/pull/3523
Discussion:
Acknowledgments:
Name: Sanket Jagtap (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RH
Bugzilla
CVE-2016-6319 foreman: Persistent XSS in Foreman remote execution plugin
bugzilla·2016-08-10·CVSS 6.1
CVE-2016-6319 [MEDIUM] CVE-2016-6319 foreman: Persistent XSS in Foreman remote execution plugin
CVE-2016-6319 foreman: Persistent XSS in Foreman remote execution plugin
Marek Hulán of Red Hat reports:
User can define a job template and specify input name containing JS code. When
someone tries to invoke such job, the form is generated based on this name
without proper escaping so the JS gets executed.
Upstream issue:
http://projects.theforeman.org/issues/16019
Proposed upstream patch:
https://github.com/theforeman/foreman/pull/3715/commits/4b63d2c7cdad76ed2bf96d9f8dff7e0c5cdabda6
Discussion:
Acknowledgments:
Name: Marek Hulán (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
2018-01-12
Published