First published: Wed Jun 20 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the Integration Solution Console in the Administration Console in IBM WebSphere Application Server 7.0 before 7.0.0.23 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =7.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0720 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2012-0720, upgrade your IBM WebSphere Application Server to version 7.0.0.23 or later.
CVE-2012-0720 affects users of IBM WebSphere Application Server versions 7.0 and its earlier updates.
Yes, CVE-2012-0720 can be exploited remotely by attackers through crafted URLs.
The potential impacts of CVE-2012-0720 include unauthorized access to sensitive information and user interactions through injected scripts.