First published: Wed Jan 20 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Workplace Web Content Management | =6.1.0.2 | |
IBM Workplace Web Content Management | =6.0.1.4 | |
IBM Workplace Web Content Management | =6.0.1.5 | |
IBM Workplace Web Content Management | =6.0.1.6 | |
IBM Workplace Web Content Management | =6.1.0.1 | |
=6.0.1.4 | ||
=6.0.1.5 | ||
=6.0.1.6 | ||
=6.1.0.1 | ||
=6.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0357 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2010-0357, apply the appropriate iFix update for your affected version of IBM Lotus Web Content Management.
CVE-2010-0357 affects IBM Lotus Web Content Management versions 6.0.1.4, 6.0.1.5, 6.0.1.6, 6.1.0.1, and 6.1.0.2 before their respective iFix updates.
Yes, CVE-2010-0357 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
The impact of CVE-2010-0357 includes unauthorized users potentially gaining access to sensitive information by executing malicious scripts in the web browser of end users.