CVE-2014-0952: XSS
Cross-site scripting (XSS) vulnerability in bootconfig.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF28, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0952?
CVE-2014-0952 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-0952?
To fix CVE-2014-0952, apply the recommended patches and updates provided by IBM for the affected versions of WebSphere Portal.
Which versions of IBM WebSphere Portal are affected by CVE-2014-0952?
CVE-2014-0952 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6, 6.1.5 through 6.1.5.3, 7.0 through 7.0.0.2, and 8.0 before 8.0.0.1.
Can CVE-2014-0952 be exploited remotely?
Yes, CVE-2014-0952 allows remote attackers to inject arbitrary web scripts or HTML.
What is the nature of the vulnerability in CVE-2014-0952?
CVE-2014-0952 is a cross-site scripting (XSS) vulnerability that can lead to malicious scripts being executed in the context of a user's session.