Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ibm Was | — | Upgrade to version 8.5.5.Upgrade to version 8.0.0.7.Upgrade to version 7.0.0.29.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM85834.Upgrade to minimal fix pack levels as required by interim fixes and then apply Interim Fix PM87131. | Apr 27, 2018 | Aug 21, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub