First published: Sun Jul 17 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =7.0.0.1 | |
IBM Workplace Web Content Management | ||
IBM WebSphere Portal | =7.0.0.1-cf004 | |
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1-cf005 | |
IBM WebSphere Portal | =7.0.0.1-cf003 | |
IBM WebSphere Portal | =7.0.0.1-cf002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-2754 is considered medium due to its potential for cross-site scripting attacks.
To fix CVE-2011-2754, upgrade IBM WebSphere Portal to version 7.0.0.1 or apply the relevant patches provided by IBM.
CVE-2011-2754 affects IBM WebSphere Portal versions prior to 7.0.0.1 and IBM Web Content Manager used within those versions.
CVE-2011-2754 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2011-2754 can be exploited remotely by attackers to execute arbitrary scripts on victims' browsers.