CVE-2008-0869: XSS
Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0869?
CVE-2008-0869 is categorized as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2008-0869?
To mitigate CVE-2008-0869, apply the latest patches provided by Oracle for affected versions of WebLogic Server and WebLogic Workshop.
What software is affected by CVE-2008-0869?
CVE-2008-0869 affects BEA WebLogic Workshop versions 8.1 through SP6 and WebLogic Server versions 9.0 through 10.0.
What type of vulnerability is CVE-2008-0869?
CVE-2008-0869 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Can CVE-2008-0869 lead to data breaches?
Yes, if exploited, CVE-2008-0869 could lead to data breaches by allowing attackers to execute malicious scripts in the context of a user's session.