CVE-2014-0917: XSS
Cross-site scripting (XSS) vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0917?
CVE-2014-0917 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2014-0917?
To fix CVE-2014-0917, upgrade your IBM WebSphere Portal to a version that is not vulnerable, specifically to 8.0.0.1 or later.
What versions of IBM WebSphere Portal are affected by CVE-2014-0917?
CVE-2014-0917 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06.
What type of attack can be performed using CVE-2014-0917?
CVE-2014-0917 allows remote attackers to inject arbitrary web scripts or HTML via a crafted URL.
What systems are vulnerable to CVE-2014-0917?
Systems running certain versions of IBM WebSphere Portal, specifically those listed in the CVE details, are vulnerable to CVE-2014-0917.