Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-php/PEAR-Mail.Upgrade dev-php/PEAR-PEAR.Upgrade net-libs/libsoup.Upgrade media-libs/xine-lib.Upgrade games-sports/racer-bin.Upgrade sys-apps/shadow.Upgrade net-misc/vino.Upgrade dev-vcs/gitolite.Upgrade x11-apps/xrdb.Upgrade media-libs/fmod.Upgrade dev-db/unixODBC.Upgrade net-misc/mrouted.Upgrade gnome-base/gdm.Upgrade app-admin/syslog-ng.Upgrade dev-util/oprofile.Upgrade dev-libs/xmlsec.Upgrade dev-util/qt-creator.Upgrade sys-cluster/resource-agents.Upgrade sys-fs/lvm2.Upgrade net-analyzer/sflowtool.Upgrade app-office/gnucash.Upgrade net-libs/webkit-gtk.Upgrade media-sound/lastfmplayer.Upgrade app-misc/ca-certificates.Upgrade net-misc/rsync. | Oct 30, 2017 | Jun 24, 2010 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM11777.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM11778.Upgrade to version 6.1.0.33.Upgrade to version 7.0.0.11. | Apr 27, 2018 | Jun 24, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub