CVE-2010-2433: XSS
Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.
Affected Software
Event History
Frequently Asked Questions
What are the vulnerable components affected by CVE-2010-2433?
CVE-2010-2433 affects content/internalError.jsp and allows XSS attacks via RTS URL inputs to explore/explore.jsp, compose/compose.jsp, or home.jsp.
What is the impact of CVE-2010-2433?
CVE-2010-2433 allows remote attackers to execute arbitrary web scripts or HTML in the context of affected users' browsers.
How do I fix CVE-2010-2433?
To mitigate CVE-2010-2433, update to a patched version of IBM WebSphere ILOG JRules or employ input validation measures.
What versions of IBM WebSphere ILOG JRules are affected by CVE-2010-2433?
CVE-2010-2433 affects IBM WebSphere ILOG JRules version 6.7.
Can CVE-2010-2433 lead to data theft?
Yes, CVE-2010-2433 can lead to data theft by allowing attackers to execute scripts that can steal sensitive user information.