Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.802413
Category:Web Servers
Title:IBM WebSphere Application Server 6.1.x < 6.1.0.41, 7.0.x < 7.0.0.19 IVT XSS Vulnerability
Summary:IBM WebSphere Application Server is prone to a cross-site; scripting (XSS) vulnerability.
Description:Summary:
IBM WebSphere Application Server is prone to a cross-site
scripting (XSS) vulnerability.

Vulnerability Insight:
The flaw is due to an error in Installation Verification Test
(IVT) application in the Install component, which allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.

Vulnerability Impact:
Successful exploitation will let attackers to conduct cross-site
scripting attacks.

Affected Software/OS:
IBM WebSphere Application Server version 6.1.x prior to
6.1.0.41 and 7.0.x prior to 7.0.0.19.

Solution:
Update to version 6.1.0.41, 7.0.0.19 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1362
AIX APAR: PM40733
http://www-01.ibm.com/support/docview.wss?uid=swg1PM40733
AIX APAR: PM65992
http://www-01.ibm.com/support/docview.wss?uid=swg1PM65992
XForce ISS Database: was-incomplete-ivt-xss(69731)
https://exchange.xforce.ibmcloud.com/vulnerabilities/69731
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.