![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-4770 |
Description: | Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-4770 AIX APAR: PI23055 http://www-01.ibm.com/support/docview.wss?uid=swg1PI23055 BugTraq ID: 69981 http://www.securityfocus.com/bid/69981 CERT/CC vulnerability note: VU#573356 http://www.kb.cert.org/vuls/id/573356 http://secunia.com/advisories/61418 http://secunia.com/advisories/61423 XForce ISS Database: ibm-websphere-cve20144770-xss(95209) https://exchange.xforce.ibmcloud.com/vulnerabilities/95209 |