CVE-2014-0828: XSS
Cross-site scripting (XSS) vulnerability in the WCM (Web Content Manager) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0828?
CVE-2014-0828 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-0828?
To fix CVE-2014-0828, apply the latest patches or updates provided by IBM for affected versions of WebSphere Portal.
Which versions are affected by CVE-2014-0828?
CVE-2014-0828 affects IBM WebSphere Portal versions 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF11.
What type of vulnerability is CVE-2014-0828?
CVE-2014-0828 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2014-0828 be exploited remotely?
Yes, CVE-2014-0828 allows remote attackers to inject arbitrary web scripts or HTML into the Web Content Manager UI.