PatchSiren cyber security CVE debrief
CVE-2016-5880 IBM CVE debrief
CVE-2016-5880 is a cross-site scripting vulnerability in IBM iNotes that can let a user embed arbitrary JavaScript in the web UI. The impact described in the record is alteration of intended functionality and possible credential disclosure within a trusted session. NVD rates the issue as medium severity (CVSS 5.4) and ties it to CWE-79.
- Vendor
- IBM
- Product
- Domino
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
IBM iNotes and IBM Domino administrators, especially teams supporting webmail/web UI access, should treat this as relevant because the attack path depends on a user interacting with crafted content inside a trusted session.
Technical summary
The NVD record describes an XSS issue in IBM iNotes. The CVSS 3.0 vector is AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, indicating a network-reachable attack that requires low privileges and user interaction, with limited confidentiality and integrity impact but changed scope. NVD lists affected IBM Domino and IBM iNotes versions across the 8.5.1 through 9.0.1.6 lines.
Defensive priority
Medium priority. The vulnerability is not availability-focused, but it can expose credentials or enable action spoofing in a trusted web session, so patching and validation should be scheduled promptly for any exposed IBM iNotes deployment.
Recommended defensive actions
- Apply the IBM fix or guidance referenced in the vendor advisory linked from NVD.
- Verify which IBM iNotes and IBM Domino versions in your environment match the affected CPE ranges listed by NVD.
- Review web UI input handling and output encoding controls for user-supplied content.
- Reassess session protections for iNotes users, especially where trusted browser sessions are used.
- Track any residual exposure by limiting access to patched systems until remediation is confirmed.
Evidence notes
All substantive claims are supported by the NVD record and its cited IBM advisory. The official record was published on 2017-02-01 and later modified on 2026-05-13; that modified date reflects database maintenance, not the original vulnerability date.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-5880 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-5880
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-5880 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5880
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.