CVE-2007-5798: XSS
Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Systems running the UDDI user console in affected IBM WebSphere Application Server versions are exposed because the vulnerable navigateTree.do endpoint can be reached remotely. The issue affects versions before 6.1.0 Fix Pack 13 (6.1.0.13).
What does an attacker need to exploit this issue?
An attacker does not need authentication, but must be able to send crafted requests to uddigui/navigateTree.do. The vulnerable inputs are keyField, nameField, valueField, and frameReturn.
What is the remediation?
Update IBM WebSphere Application Server to Fix Pack 13 for version 6.1.0 or later. The provided information does not identify an alternative mitigation for systems that cannot be patched immediately.