CVE-2009-0856: XSS
Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0856?
CVE-2009-0856 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2009-0856?
To fix CVE-2009-0856, upgrade to IBM WebSphere Application Server versions 6.0.2.35 or 6.1.0.23 or later.
Which versions of IBM WebSphere Application Server are affected by CVE-2009-0856?
CVE-2009-0856 affects versions 6.0.2 before 6.0.2.35 and all 6.1 versions before 6.1.0.23.
What types of vulnerabilities are present in CVE-2009-0856?
CVE-2009-0856 presents multiple cross-site scripting (XSS) vulnerabilities that allow attackers to inject arbitrary web script or HTML.
Is IBM WebSphere Application Server version 6.1.0.22 affected by CVE-2009-0856?
No, IBM WebSphere Application Server version 6.1.0.22 is not affected by CVE-2009-0856.