PT-2014-3896 · Ibm · Ibm Websphere Portal+1

Publicado

2014-02-14

·

Atualizado

2017-08-29

·

CVE-2014-0855

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Connections Portlets versions prior to 4.5.1 FP1 IBM WebSphere Portal versions 7.0.0.2 and 8.0.0.1
Description The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which can lead to multiple cross-site scripting (XSS) vulnerabilities.
Recommendations For IBM Connections Portlets versions prior to 4.5.1 FP1, update to version 4.5.1 FP1 or later. For IBM WebSphere Portal versions 7.0.0.2 and 8.0.0.1, consider restricting access to sensitive areas of the portal until an update or patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0855

Produtos afetados

Ibm Connections Portlets
Ibm Websphere Portal