IBM Support

IV83117: TITLE: TINY MCE NOTE EDITOR. ALLOWS YOU TO ENTER HTML TEXT THAT FIRES AN ALERT (HTML EDIT LINK)

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as fixed if next.

Error description

  • A Cross Site Scripting (XSS) attack occurs when an attacker
    uses a web application to inject malicious code in the form of
    a client side script  arbitrary JavaScript  to an end user.
    
    ONE EXAMPLE OF MANY THROUGHOUT THE APPLICAITON:
    
    Attack value: <p>123</p><p><input onclick="alert(1234)"
    type="text"/></p>
    
    1. Login into application
    2. Click on Help link
    3. Click on HTML link of the editor to open HTML Source Editor
    4. Apply attack value and click on UPDATE button
    5. Click on Save button
    6. Click on recently added value
    

Local fix

  • N/A
    

Problem summary

  • Need ability to disable HTML Editor in Note Fields.
    

Problem conclusion

  • A new property is added in TRIRIGAWEB.properties file called
    TINYMCE_HTML_EDITOR_ENABLED. This property will determine if
    "HTML Editor" button will be displayed in form notes field. By
    default the value of this property is set to true, which will
    display the button in notes field. Note fields are vulnerable
    to attack if the button is enabled. This is targeted to the
    1H2016 release, as well as the 3.5.0.2 fix pack.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV83117

  • Reported component name

    TRI APP PLTFM R

  • Reported component ID

    5725F26RE

  • Reported release

    350

  • Status

    CLOSED FIN

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-03-29

  • Closed date

    2016-04-03

  • Last modified date

    2025-06-10

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • 999
    

Fix information

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSHEB3","label":"IBM TRIRIGA Application Platform"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"350","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Document Information

Modified date:
10 June 2025