First published: Wed Nov 26 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | <=7.0.0.2 | |
IBM WebSphere Portal | <=8.0.0.1 | |
IBM WebSphere Portal | <=8.5.0.0 | |
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =8.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6093 is categorized with a medium severity rating due to its cross-site scripting (XSS) vulnerability that can be exploited by authenticated users.
To mitigate CVE-2014-6093, upgrade to IBM WebSphere Portal versions 7.0.0.2 CF29 or later, 8.0.0.1 CF14 or later, or 8.5.0 CF02 or later.
Remote authenticated users can exploit CVE-2014-6093 by injecting arbitrary web script or HTML through crafted URLs.
IBM WebSphere Portal versions 7.0.0.0 to 7.0.0.1, 8.0.0.0 to 8.0.0.1, and 8.5.0.0 are affected by CVE-2014-6093.
Yes, CVE-2014-6093 poses a serious security risk as it allows attackers to inject malicious scripts which can compromise user data.