CVE-2014-6215: XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6215?
CVE-2014-6215 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2014-6215?
To remediate CVE-2014-6215, you should apply the necessary IBM WebSphere Portal patches as per the IBM fixes for the affected versions.
Which versions of IBM WebSphere Portal are affected by CVE-2014-6215?
CVE-2014-6215 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6, 6.1.5 through 6.1.5.3, 7.0.0 before 7.0.0.2, 8.0.0 through 8.0.0.1, and 8.5.0 before CF03.
Can CVE-2014-6215 be exploited remotely?
Yes, CVE-2014-6215 can be exploited remotely by authenticated users through specially crafted URLs.
What type of vulnerability is CVE-2014-6215?
CVE-2014-6215 is a cross-site scripting (XSS) vulnerability.