First published: Sun Oct 30 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.12 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.21 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.23 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.25 | |
IBM WebSphere Application Server Feature Pack for Web Services | =6.1.0.27 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2748 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2009-2748, upgrade IBM WebSphere Application Server to version 6.1.0.29 or later for 6.1 and to version 7.0.0.7 or later for 7.1.
CVE-2009-2748 affects IBM WebSphere Application Server versions 6.1.0.0 through 6.1.0.28 and 7.0.0.1 through 7.0.0.6.
Yes, CVE-2009-2748 can be exploited remotely by attackers to inject arbitrary web script or HTML.
While CVE-2009-2748 is specific to certain versions of IBM WebSphere, cross-site scripting vulnerabilities are common across web applications.