Zero-Day Advisory
Fortinet Discovers IBM Lotus Protector for Mail Security Cross-Site Scripting Vulnerability
Summary
Fortinet's FortiGuard Labs has discovered a cross-site scripting vulnerability in IBM Lotus Protector for Mail Security.
IBM Lotus Protector for Mail Security scans email messages and attached files for unwanted, confidential or malicious content, extending email security and compliance for social business platform. It controls the email content that enters and leaves the company's network to ensure a high level of email security and blocks spam and viruses.
A cross-site scripting vulnerability exists in IBM Lotus Protector for Mail Security. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:IBM.Lotus.Protector.XSS
Released Jul 12, 2016
FortiWeb can cover this specific vulnerability with following signatures:
Cross Site Scripting 010000000
Cross Site Scripting (Extended) 020000000
Users should apply the solution provided by IBM.