CVE-2016-2884: IBM Forms Experience Builder
High severity, CVSS 8.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Affected products
- IBM Forms Experience Builder: version 8.5.0.0 only; version 8.5.1.0 only; version 8.5.1.1 only; version 8.6.0.0 only; version 8.6.1 only; version 8.6.1.1 only; …
Published 2016-11-30. Last modified 2026-06-17.