CVE-2016-3049

Severity
5.4MEDIUM
EPSS
0.2%
top 60.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateMay 17

Description

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

NVDibm/openpages_grc_platform7.1, 7.2, 7.3+2

🔴Vulnerability Details

2
GHSA
GHSA-2m29-qmgp-4p6h: IBM OpenPages GRC Platform 72022-05-17
CVEList
CVE-2016-3049: IBM OpenPages GRC Platform 72017-10-24
CVE-2016-3049 (MEDIUM CVSS 5.4) | IBM OpenPages GRC Platform 7.1 | cvebase.io