PT-2016-3651 · Ibm · Ibm Websphere Commerce
Publicado
2016-01-18
·
Atualizado
2019-09-30
·
CVE-2015-5008
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Commerce versions 6.0 through FP11
IBM WebSphere Commerce version 6.0 Feature Pack 4
IBM WebSphere Commerce versions 7.0 through FP9
IBM WebSphere Commerce versions 7.0 Feature Pack 5 through 8
IBM WebSphere Commerce versions 8.0 before 8.0.0.1
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Recommendations
For IBM WebSphere Commerce versions 6.0 through FP11, update to a version after FP11.
For IBM WebSphere Commerce version 6.0 Feature Pack 4, update to a version after Feature Pack 4.
For IBM WebSphere Commerce versions 7.0 through FP9, update to a version after FP9.
For IBM WebSphere Commerce versions 7.0 Feature Pack 5 through 8, update to a version after 8.
For IBM WebSphere Commerce versions 8.0 before 8.0.0.1, update to version 8.0.0.1 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Websphere Commerce