First published: Fri May 30 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before 6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Service Registry and Repository | =6.2.0 | |
IBM WebSphere Service Registry and Repository | =6.3.0 | |
IBM WebSphere Service Registry and Repository | =6.3.0.1 | |
IBM WebSphere Service Registry and Repository | =6.3.0.2 | |
IBM WebSphere Service Registry and Repository | =6.3.0.3 | |
IBM WebSphere Service Registry and Repository | =6.3.0.4 | |
IBM WebSphere Service Registry and Repository | =6.3.0.5 | |
IBM WebSphere Service Registry and Repository | =7.0.0 | |
IBM WebSphere Service Registry and Repository | =7.0.0.1 | |
IBM WebSphere Service Registry and Repository | =7.0.0.2 | |
IBM WebSphere Service Registry and Repository | =7.0.0.3 | |
IBM WebSphere Service Registry and Repository | =7.0.0.4 | |
IBM WebSphere Service Registry and Repository | =7.0.0.5 | |
IBM WebSphere Service Registry and Repository | =7.5.0.1 | |
IBM WebSphere Service Registry and Repository | =7.5.0.2 | |
IBM WebSphere Service Registry and Repository | =7.5.0.3 | |
IBM WebSphere Service Registry and Repository | =7.5.0.4 | |
IBM WebSphere Service Registry and Repository | =7.5.0.5 | |
IBM WebSphere Service Registry and Repository | =8.0.0 | |
IBM WebSphere Service Registry and Repository | =8.0.0.1 | |
IBM WebSphere Service Registry and Repository | =8.0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3010 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2014-3010, you should update IBM WebSphere Service Registry and Repository to version 6.3.0.6, 7.0.0.6, 7.5.0.5, or 8.0.0.3 or later.
CVE-2014-3010 affects versions 6.2, 6.3 (up to 6.3.0.5), 7.0 (up to 7.0.0.5), 7.5 (up to 7.5.0.4), and 8.0 (up to 8.0.0.2) of IBM WebSphere Service Registry and Repository.
CVE-2014-3010 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Yes, if you are using an affected version of IBM WebSphere Service Registry and Repository, CVE-2014-3010 can compromise your web application.