CVE-2012-0720: XSS
Published Jun 20, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
16 affected components
IBM WebSphere Application Server Feature Pack for Web Services=7.0
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.1
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.2
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.3
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.4
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.5
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.6
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.7
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.8
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.9
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.11
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.13
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.15
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.17
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.19
IBM WebSphere Application Server Feature Pack for Web Services=7.0.0.21
Event History
Jun 20, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0720?
CVE-2012-0720 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2012-0720?
To fix CVE-2012-0720, upgrade your IBM WebSphere Application Server to version 7.0.0.23 or later.
3
Who is affected by CVE-2012-0720?
CVE-2012-0720 affects users of IBM WebSphere Application Server versions 7.0 and its earlier updates.
4
Can CVE-2012-0720 be exploited remotely?
Yes, CVE-2012-0720 can be exploited remotely by attackers through crafted URLs.
5
What are the potential impacts of CVE-2012-0720?
The potential impacts of CVE-2012-0720 include unauthorized access to sensitive information and user interactions through injected scripts.