CVE-2011-1102: XSS
Cross-site scripting (XSS) vulnerability in the WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1102?
CVE-2011-1102 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2011-1102?
To fix CVE-2011-1102, install the appropriate hotfix for your version of F-Secure Policy Manager.
Which versions of F-Secure Policy Manager are affected by CVE-2011-1102?
CVE-2011-1102 affects versions of F-Secure Policy Manager prior to hotfix 2 on 8.00, prior to hotfix 3 on 8.1x, and prior to hotfix 4 on 9.00.
What are the potential impacts of CVE-2011-1102?
The potential impacts of CVE-2011-1102 include unauthorized execution of arbitrary web scripts or HTML in the context of a user's session.
Who can exploit CVE-2011-1102?
CVE-2011-1102 can be exploited by remote attackers to perform cross-site scripting attacks.