PatchSiren cyber security CVE debrief
CVE-2016-5881 IBM CVE debrief
CVE-2016-5881 is a cross-site scripting vulnerability in IBM iNotes. According to the NVD record and IBM-linked references, affected users could embed arbitrary JavaScript in the web UI, altering intended behavior and potentially exposing credentials within a trusted session. NVD lists the issue as medium severity (CVSS 6.1) and maps it to CWE-79.
- Vendor
- IBM
- Product
- Inotes
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-01
- Advisory updated
- 2026-05-13
Who should care
IBM iNotes administrators, messaging/collaboration platform owners, and security teams responsible for web-accessible iNotes deployments or trusted-session/SSO environments should care most. This is especially important where users can reach the web UI over the network and where browser session integrity matters.
Technical summary
NVD classifies CVE-2016-5881 as CWE-79 (cross-site scripting) with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The attack is network-reachable, requires no privileges, but does require user interaction. NVD’s affected CPEs include IBM iNotes versions 8.5.1.0 through 8.5.3.6 and 9.0.0.0 through 9.0.1.6 as enumerated in the record. The primary security impact is limited confidentiality and integrity exposure, with no availability impact noted.
Defensive priority
Medium. Prioritize remediation sooner if IBM iNotes is exposed to many users, used in SSO/trusted-session workflows, or accessible from less controlled networks.
Recommended defensive actions
- Confirm whether any deployed IBM iNotes instances match the affected versions listed by NVD.
- Follow IBM PSIRT guidance from the vendor advisory reference and apply the relevant IBM update or mitigation for the installed release.
- Review the web UI for any user-controlled content paths or custom integrations that could permit script injection.
- Limit access to the iNotes web interface to trusted users and networks where possible.
- Monitor for signs of unexpected script execution, session abuse, or credential exposure, and rotate credentials if exposure is suspected.
Evidence notes
This debrief is based on the supplied NVD record and its reference metadata. The record identifies IBM as the vendor, cites an IBM PSIRT advisory, and maps the issue to CWE-79 with CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The published date in the supplied corpus is 2017-02-01; the later modified date should not be treated as the issue date.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-5881 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-5881
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-5881 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-5881
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.