CVE-2014-6180: XSS
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the HTTP User-Agent header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6180?
CVE-2014-6180 has a medium severity rating as it allows remote authenticated users to inject arbitrary web script or HTML.
How do I fix CVE-2014-6180?
To fix CVE-2014-6180, update IBM WebSphere Service Registry and Repository to version 7.0.0.5 or 7.5.0.1 or later.
Who is affected by CVE-2014-6180?
CVE-2014-6180 affects users of IBM WebSphere Service Registry and Repository versions 7.0.x before 7.0.0.5 and 7.5.x before 7.5.0.1.
What type of vulnerability is CVE-2014-6180?
CVE-2014-6180 is a cross-site scripting (XSS) vulnerability.
What is the impact of CVE-2014-6180?
The impact of CVE-2014-6180 includes unauthorized access to user sessions and potential data theft.