CVE-2014-0951: XSS
Cross-site scripting (XSS) vulnerability in FilterForm.jsp in IBM WebSphere Portal 7.0 before 7.0.0.2 CF28 and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0951?
CVE-2014-0951 has been rated as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2014-0951?
To fix CVE-2014-0951, upgrade IBM WebSphere Portal to version 7.0.0.2 or 8.0.0.1 or later.
What types of attacks can exploit CVE-2014-0951?
CVE-2014-0951 can be exploited through cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
Which versions of IBM WebSphere Portal are affected by CVE-2014-0951?
CVE-2014-0951 affects IBM WebSphere Portal versions 6.1, 7.0 prior to 7.0.0.2, and 8.0 prior to 8.0.0.1.
Does CVE-2014-0951 require authentication for exploitation?
CVE-2014-0951 can potentially be exploited without authentication, making it more critical for users to address this vulnerability.