Direct links to fixes
APAR status
Closed as fixed if next.
Error description
A Cross Site Scripting (XSS) attack occurs when an attacker uses a web application to inject malicious code in the form of a client side script arbitrary JavaScript to an end user. ONE EXAMPLE OF MANY THROUGHOUT THE APPLICAITON: Attack value: <p>123</p><p><input onclick="alert(1234)" type="text"/></p> 1. Login into application 2. Click on Help link 3. Click on HTML link of the editor to open HTML Source Editor 4. Apply attack value and click on UPDATE button 5. Click on Save button 6. Click on recently added value
Local fix
N/A
Problem summary
Need ability to disable HTML Editor in Note Fields.
Problem conclusion
A new property is added in TRIRIGAWEB.properties file called TINYMCE_HTML_EDITOR_ENABLED. This property will determine if "HTML Editor" button will be displayed in form notes field. By default the value of this property is set to true, which will display the button in notes field. Note fields are vulnerable to attack if the button is enabled. This is targeted to the 1H2016 release, as well as the 3.5.0.2 fix pack.
Temporary fix
Comments
APAR Information
APAR number
IV83117
Reported component name
TRI APP PLTFM R
Reported component ID
5725F26RE
Reported release
350
Status
CLOSED FIN
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2016-03-29
Closed date
2016-04-03
Last modified date
2025-06-10
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Modules/Macros
999
Fix information
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSHEB3","label":"IBM TRIRIGA Application Platform"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"350","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]
Document Information
Modified date:
10 June 2025