CVE-2016-8948
published 2017-07-12CVE-2016-8948: IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.73%
49.9th percentile
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118835.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | libidn | >= 0 < 1.28-1ubuntu2.1 | 1.28-1ubuntu2.1 |
| gnu | libidn | >= 0 < 1.32-3ubuntu1.1 | 1.32-3ubuntu1.1 |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r2hv-r9qv-hmpw: IBM Emptoris Sourcing 9
ghsa_unreviewed·2022-05-17
CVE-2016-8948 [MEDIUM] CWE-79 GHSA-r2hv-r9qv-hmpw: IBM Emptoris Sourcing 9
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118835.
OSV
libidn vulnerabilities
osv·2016-08-24·CVSS 7.5
CVE-2015-2059 libidn vulnerabilities
libidn vulnerabilities
Thijs Alkemade, Gustavo Grieco, Daniel Stenberg, and Nikos
Mavrogiannopoulos discovered that Libidn incorrectly handled invalid UTF-8
characters. A remote attacker could use this issue to cause Libidn to
crash, resulting in a denial of service, or possibly disclose sensitive
memory. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2015-2059)
Hanno Böck discovered that Libidn incorrectly handled certain input. A
remote attacker could possibly use this issue to cause Libidn to crash,
resulting in a denial of service. (CVE-2015-8948, CVE-2016-6262,
CVE-2016-6261, CVE-2016-6263)
Red Hat
libidn: Out-of-bounds read when reading zero byte as input
vendor_redhat·2016-01-14·CVSS 7.5
CVE-2016-6262 [HIGH] CWE-125 libidn: Out-of-bounds read when reading zero byte as input
libidn: Out-of-bounds read when reading zero byte as input
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
Package: libidn (Red Hat Enterprise Linux 5) - Will not fix
Package: libidn (Red Hat Enterprise Linux 6) - Will not fix
Package: libidn (Red Hat Enterprise Linux 7) - Will not fix
No detection rules found.
http://www.ibm.com/support/docview.wss?uid=swg22005549http://www.securityfocus.com/bid/99545https://exchange.xforce.ibmcloud.com/vulnerabilities/118835http://www.ibm.com/support/docview.wss?uid=swg22005549http://www.securityfocus.com/bid/99545https://exchange.xforce.ibmcloud.com/vulnerabilities/118835
2017-07-12
Published