First published: Mon Sep 20 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-016 allows remote attackers to inject arbitrary web script or HTML via the Name field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FileNet P8 Application Engine | =3.5.1-009 | |
IBM FileNet P8 Application Engine | =3.5.1-011 | |
IBM FileNet P8 Application Engine | =3.5.1-005 | |
IBM FileNet P8 Application Engine | =3.5.1-014 | |
IBM FileNet P8 Application Engine | =3.5.1-006 | |
IBM FileNet P8 Application Engine | =3.5.1-013 | |
IBM FileNet P8 Application Engine | =3.5.1-004 | |
IBM FileNet P8 Application Engine | =3.5.1 | |
IBM FileNet P8 Application Engine | =3.5.1-007 | |
IBM FileNet P8 Application Engine | =3.5.1-001 | |
IBM FileNet P8 Application Engine | =3.5.1-012 | |
IBM FileNet P8 Application Engine | =3.5.1-015 | |
IBM FileNet P8 Application Engine | =3.5.1-010 | |
IBM FileNet P8 Application Engine | =3.5.1-002 | |
IBM FileNet P8 Application Engine | =3.5.1-008 | |
IBM FileNet P8 Application Engine | =3.5.1-003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4999 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2009-4999, upgrade IBM FileNet P8 Application Engine to version 3.5.1-016 or later.
CVE-2009-4999 affects various versions of IBM FileNet P8 Application Engine 3.5.1 including 001 through 015.
CVE-2009-4999 allows remote attackers to inject arbitrary web script or HTML into the Name field.
Organizations using vulnerable versions of IBM FileNet P8 Application Engine are at risk of exploitation from CVE-2009-4999.