PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-0265 IBM CVE debrief

CVE-2016-0265 is a cross-site scripting (XSS) issue in IBM Campaign. According to NVD and the cited IBM PSIRT reference, improper validation of user-supplied input can allow a remote attacker to use a specially crafted URL to execute script in a victim’s browser after the link is clicked. The impact includes theft of cookie-based authentication credentials.

Vendor
IBM
Product
Campaign
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-01
Original CVE updated
2026-05-13
Advisory published
2017-02-01
Advisory updated
2026-05-13

Who should care

IBM Campaign administrators, application security teams, and anyone operating or supporting affected IBM Campaign deployments should review this issue, especially if users can receive or click Campaign URLs.

Technical summary

NVD classifies the weakness as CWE-79 and lists CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The vulnerable product coverage in the NVD record includes IBM Campaign 8.6, 9.1, 9.1.1, and 9.1.2. The issue is URL-triggered XSS: user-controlled input is not validated adequately, allowing script execution in the context of the hosting site when a victim clicks the crafted link.

Defensive priority

Medium. The issue requires user interaction and some access context, but it can still enable session theft or unauthorized actions in affected web sessions.

Recommended defensive actions

  • Apply the IBM fix or vendor guidance referenced by the IBM PSIRT advisory link.
  • Review any IBM Campaign functionality that reflects or processes URL parameters or other user-controlled input.
  • Ensure application output encoding and input validation are consistently enforced in the affected code paths.
  • Harden session handling to reduce the value of stolen cookies, including using secure cookie attributes where appropriate.
  • Monitor for unexpected script injection indicators in application logs and user-reported browser behavior.
  • Confirm which IBM Campaign versions are deployed and prioritize remediation for the affected versions listed by NVD.

Evidence notes

This debrief is based on the supplied NVD record and its references. NVD identifies CWE-79 and a CVSS v3.0 vector of AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The record lists affected IBM Campaign CPEs for versions 8.6, 9.1, 9.1.1, and 9.1.2. NVD also includes an IBM PSIRT vendor advisory/patched reference and a SecurityFocus VDB entry reference. No KEV designation was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-0265 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-0265

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-0265 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-0265

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.