Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-8909

Overview

Vulnerability Score 3.5 3.5
CVE Id CVE-2014-8909
Last Modified 13 Feb 2015 06:20:35
Published 12 Feb 2015 09:59:08
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication SINGLE_INSTANCE

CVE-2014-8909

Summary

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF29, 8.0.0.x before 8.0.0.1 CF15, and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Vulnerable Systems

Application

  • Ibm Websphere Portal 6.1.0.0

  • Ibm Websphere Portal 6.1.0.1

  • Ibm Websphere Portal 6.1.0.2

  • Ibm Websphere Portal 6.1.0.3

  • Ibm Websphere Portal 6.1.0.4

  • Ibm Websphere Portal 6.1.0.5

  • Ibm Websphere Portal 6.1.0.6

  • Ibm Websphere Portal 6.1.5.0

  • Ibm Websphere Portal 6.1.5.1

  • Ibm Websphere Portal 6.1.5.2

  • Ibm Websphere Portal 6.1.5.3

  • Ibm Websphere Portal 7.0.0.0

  • Ibm Websphere Portal 7.0.0.1

  • Ibm Websphere Portal 8.0.0.0


References

XF - ibm-wsportal-cve20148909-xss(99250)

CONFIRM - http://www-01.ibm.com/support/docview.wss?uid=swg21694738

AIXAPAR - PI30620


Last Updated: 27 May 2016 11:07:48