PT-2015-4519 · Ibm · Websphere Portal+1

Publicado

2015-10-03

·

Atualizado

2015-10-05

·

CVE-2015-0195

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Content Template Catalog versions 4.0 through 4.1.3 for WebSphere Portal 8.0.x IBM Content Template Catalog versions 4.0 through 4.3.0 for WebSphere Portal 8.5.x
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a crafted URL. This can lead to the execution of malicious code on the victim's browser.
Recommendations For IBM Content Template Catalog versions 4.0 through 4.1.3 for WebSphere Portal 8.0.x, update to version 4.1.4 or later. For IBM Content Template Catalog versions 4.0 through 4.3.0 for WebSphere Portal 8.5.x, update to version 4.3.1 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-0195

Produtos afetados

Ibm Content Template Catalog
Websphere Portal