CVE-2014-0910: XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0910?
CVE-2014-0910 has a medium severity rating due to its potential for cross-site scripting.
How do I fix CVE-2014-0910?
To fix CVE-2014-0910, update your IBM WebSphere Portal to a patched version provided by IBM.
Which versions of IBM WebSphere Portal are affected by CVE-2014-0910?
CVE-2014-0910 affects IBM WebSphere Portal versions 6.1.0.0 through 6.1.0.6, 6.1.5.0 through 6.1.5.3, and 7.0.0 through 7.0.0.2.
What types of attacks are possible with CVE-2014-0910?
CVE-2014-0910 allows remote authenticated users to execute arbitrary web script or HTML, leading to cross-site scripting attacks.
Who can exploit CVE-2014-0910?
CVE-2014-0910 can be exploited by remote authenticated users with access to the affected IBM WebSphere Portal.