CVE-2009-2742: XSS
Published Sep 21, 2009
·Updated
Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.
Affected Software
15 affected components
IBM WebSphere Application Server Feature Pack for Web Services=6.1
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.1
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.2
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.3
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.5
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.7
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.9
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.11
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.13
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.15
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.17
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.19
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.21
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.23
IBM WebSphere Application Server Feature Pack for Web Services=6.1.0.25
Remediation
Patch Available
Event History
Sep 21, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2742?
CVE-2009-2742 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2009-2742?
To fix CVE-2009-2742, upgrade your IBM WebSphere Application Server to the latest version after 6.1.0.27.
3
Which versions of IBM WebSphere Application Server are affected by CVE-2009-2742?
CVE-2009-2742 affects several versions of IBM WebSphere Application Server 6.1, including 6.1.0.1 up to 6.1.0.25.
4
What type of vulnerability is CVE-2009-2742?
CVE-2009-2742 is a cross-site scripting (XSS) vulnerability.
5
Who can be impacted by CVE-2009-2742?
Remote attackers can exploit CVE-2009-2742 to inject arbitrary web scripts or HTML into affected IBM WebSphere Application Server instances.