CVE-2014-0953: XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0953?
CVE-2014-0953 has a high severity level due to its potential for remote exploitation through cross-site scripting.
How do I fix CVE-2014-0953?
To fix CVE-2014-0953, it is recommended to upgrade to the latest version of IBM WebSphere Portal that has addressed this vulnerability.
Which versions of IBM WebSphere Portal are affected by CVE-2014-0953?
CVE-2014-0953 affects IBM WebSphere Portal versions from 6.1.0.0 through 6.1.0.6, 6.1.5.0 through 6.1.5.3, 7.0.0 through 7.0.0.2, and all versions before 8.0.0.1.
What type of attack is possible with CVE-2014-0953?
CVE-2014-0953 allows an attacker to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Is CVE-2014-0953 a critical vulnerability?
While CVE-2014-0953 is classified as high severity, its criticality depends on the specific context of its deployment and potential impact.