CVE-2014-3071: XSS
Published Jul 26, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Data Quality Console in IBM InfoSphere Information Server 11.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL for adding a project connection.
Affected Software
1 affected component
IBM InfoSphere Information Server=11.3
Event History
Jul 26, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3071?
CVE-2014-3071 is rated as having a medium severity due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-3071?
To fix CVE-2014-3071, apply the appropriate security patches provided by IBM for InfoSphere Information Server 11.3.
3
What type of vulnerability is CVE-2014-3071?
CVE-2014-3071 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2014-3071?
CVE-2014-3071 affects users of IBM InfoSphere Information Server version 11.3.
5
Can CVE-2014-3071 be exploited remotely?
Yes, CVE-2014-3071 can be exploited remotely through crafted URLs.