CVE-2014-6178: XSS
Cross-site scripting (XSS) vulnerability in the widgets in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6178?
CVE-2014-6178 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-6178?
To fix CVE-2014-6178, upgrade IBM WebSphere Service Registry and Repository to version 7.5.0.4 or 8.0.0.3 or later.
Who is affected by CVE-2014-6178?
CVE-2014-6178 affects authenticated users of IBM WebSphere Service Registry and Repository versions earlier than 7.5.0.4 and 8.0.0.3.
What types of attacks can CVE-2014-6178 enable?
CVE-2014-6178 can enable remote authenticated users to inject malicious scripts or HTML into web applications.
Is CVE-2014-6178 a passive vulnerability?
No, CVE-2014-6178 is an active vulnerability that can be exploited by a remote authenticated attacker.