Description
IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Affected products
- IBM Corporation / Connections4.5 – 4.5
- IBM Corporation / Connections3.0 – 3.0
- IBM Corporation / Connections3.0.1 – 3.0.1
- IBM Corporation / Connections3.0.1.1 – 3.0.1.1
- IBM Corporation / Connections4.0 – 4.0
- IBM Corporation / Connections5.0 – 5.0
- IBM Corporation / Connections5.5 – 5.5