First published: Fri Feb 14 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in IBM Connections Portlets 4.x before 4.5.1 FP1 for IBM WebSphere Portal 7.0.0.2 and 8.0.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections Portlets | =4.0 | |
IBM Connections Portlets | =4.5 | |
IBM Connections Portlets | =4.5.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0855 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-0855, upgrade IBM Connections Portlets to version 4.5.1 FP1 or later.
CVE-2014-0855 affects IBM Connections Portlets versions 4.0, 4.5, and 4.5.1 prior to FP1.
CVE-2014-0855 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts.
No, IBM WebSphere Portal versions 7.0.0.2 and 8.0.0.1 are not affected by CVE-2014-0855.