Description
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected products
- IBM Corporation / iNotes9.0 – 9.0
- IBM Corporation / iNotes8.5.3 – 8.5.3
- IBM Corporation / iNotes8.5.2 – 8.5.2
- IBM Corporation / iNotes8.5.1 – 8.5.1
- IBM Corporation / iNotes8.5 – 8.5
- IBM Corporation / iNotes8.0.2 – 8.0.2
- IBM Corporation / iNotes8.5.3.6 – 8.5.3.6
- IBM Corporation / iNotes9.0.1 – 9.0.1
- IBM Corporation / iNotes8.58.5.3 – 8.58.5.3
- IBM Corporation / iNotesFix – Fix
- IBM Corporation / iNotesPack – Pack
- IBM Corporation / iNotes6 – 6
- IBM Corporation / iNotesInterim – Interim
- IBM Corporation / iNotes1 – 1
- IBM Corporation / iNotes8.5.x – 8.5.x
- IBM Corporation / iNotes8.5.1.5 – 8.5.1.5
- IBM Corporation / iNotes8.5.2.4 – 8.5.2.4
- IBM Corporation / iNotes9.0.1.7 – 9.0.1.7