CVE-2014-6171: XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6171?
The severity of CVE-2014-6171 is considered to be medium, as it allows for cross-site scripting attacks.
How do I fix CVE-2014-6171?
To fix CVE-2014-6171, update your IBM WebSphere Portal to the latest version that addresses this vulnerability.
What kind of attacks can be executed due to CVE-2014-6171?
CVE-2014-6171 allows attackers to inject arbitrary web scripts or HTML through crafted URLs.
Which versions of IBM WebSphere Portal are affected by CVE-2014-6171?
CVE-2014-6171 affects IBM WebSphere Portal versions between 6.1.0 through 6.1.0.6, 6.1.5 through 6.1.5.3, 7.0.0 through 7.0.0.2, 8.0.0 through 8.0.0.1, and 8.5.0 before CF04.
Is CVE-2014-6171 a remote vulnerability?
Yes, CVE-2014-6171 is a remote vulnerability that can be exploited by attackers without physical access to the system.