CVE-2009-2748: XSS
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2748?
CVE-2009-2748 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2009-2748?
To fix CVE-2009-2748, upgrade IBM WebSphere Application Server to version 6.1.0.29 or later for 6.1 and to version 7.0.0.7 or later for 7.1.
What software versions are affected by CVE-2009-2748?
CVE-2009-2748 affects IBM WebSphere Application Server versions 6.1.0.0 through 6.1.0.28 and 7.0.0.1 through 7.0.0.6.
Can CVE-2009-2748 be exploited remotely?
Yes, CVE-2009-2748 can be exploited remotely by attackers to inject arbitrary web script or HTML.
Is CVE-2009-2748 a common vulnerability?
While CVE-2009-2748 is specific to certain versions of IBM WebSphere, cross-site scripting vulnerabilities are common across web applications.