CVE-2014-6093: XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6093?
CVE-2014-6093 is categorized with a medium severity rating due to its cross-site scripting (XSS) vulnerability that can be exploited by authenticated users.
How do I fix CVE-2014-6093?
To mitigate CVE-2014-6093, upgrade to IBM WebSphere Portal versions 7.0.0.2 CF29 or later, 8.0.0.1 CF14 or later, or 8.5.0 CF02 or later.
Who can exploit CVE-2014-6093?
Remote authenticated users can exploit CVE-2014-6093 by injecting arbitrary web script or HTML through crafted URLs.
What versions of IBM WebSphere Portal are affected by CVE-2014-6093?
IBM WebSphere Portal versions 7.0.0.0 to 7.0.0.1, 8.0.0.0 to 8.0.0.1, and 8.5.0.0 are affected by CVE-2014-6093.
Is CVE-2014-6093 a serious security risk?
Yes, CVE-2014-6093 poses a serious security risk as it allows attackers to inject malicious scripts which can compromise user data.