CVE-2016-2884: IBM Forms Experience Builder

High severity, CVSS 8.0. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Affected products

  • IBM Forms Experience Builder: version 8.5.0.0 only; version 8.5.1.0 only; version 8.5.1.1 only; version 8.6.0.0 only; version 8.6.1 only; version 8.6.1.1 only; …

Published 2016-11-30. Last modified 2026-06-17.