PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-5880 IBM CVE debrief

CVE-2016-5880 is a cross-site scripting vulnerability in IBM iNotes that can let a user embed arbitrary JavaScript in the web UI. The impact described in the record is alteration of intended functionality and possible credential disclosure within a trusted session. NVD rates the issue as medium severity (CVSS 5.4) and ties it to CWE-79.

Vendor
IBM
Product
Domino
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-01
Original CVE updated
2026-05-13
Advisory published
2017-02-01
Advisory updated
2026-05-13

Who should care

IBM iNotes and IBM Domino administrators, especially teams supporting webmail/web UI access, should treat this as relevant because the attack path depends on a user interacting with crafted content inside a trusted session.

Technical summary

The NVD record describes an XSS issue in IBM iNotes. The CVSS 3.0 vector is AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, indicating a network-reachable attack that requires low privileges and user interaction, with limited confidentiality and integrity impact but changed scope. NVD lists affected IBM Domino and IBM iNotes versions across the 8.5.1 through 9.0.1.6 lines.

Defensive priority

Medium priority. The vulnerability is not availability-focused, but it can expose credentials or enable action spoofing in a trusted web session, so patching and validation should be scheduled promptly for any exposed IBM iNotes deployment.

Recommended defensive actions

  • Apply the IBM fix or guidance referenced in the vendor advisory linked from NVD.
  • Verify which IBM iNotes and IBM Domino versions in your environment match the affected CPE ranges listed by NVD.
  • Review web UI input handling and output encoding controls for user-supplied content.
  • Reassess session protections for iNotes users, especially where trusted browser sessions are used.
  • Track any residual exposure by limiting access to patched systems until remediation is confirmed.

Evidence notes

All substantive claims are supported by the NVD record and its cited IBM advisory. The official record was published on 2017-02-01 and later modified on 2026-05-13; that modified date reflects database maintenance, not the original vulnerability date.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-5880 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-5880

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-5880 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5880

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.