First published: Thu Dec 11 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =6.1.0 | |
IBM WebSphere Portal | =6.1.0.1 | |
IBM WebSphere Portal | =6.1.0.2 | |
IBM WebSphere Portal | =6.1.0.3 | |
IBM WebSphere Portal | =6.1.0.4 | |
IBM WebSphere Portal | =6.1.0.5 | |
IBM WebSphere Portal | =6.1.0.6 | |
IBM WebSphere Portal | =6.1.0.6-cf27 | |
IBM WebSphere Portal | =7.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.0.0.1-14 | |
IBM WebSphere Portal | =8.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6215 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
To remediate CVE-2014-6215, you should apply the necessary IBM WebSphere Portal patches as per the IBM fixes for the affected versions.
CVE-2014-6215 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6, 6.1.5 through 6.1.5.3, 7.0.0 before 7.0.0.2, 8.0.0 through 8.0.0.1, and 8.5.0 before CF03.
Yes, CVE-2014-6215 can be exploited remotely by authenticated users through specially crafted URLs.
CVE-2014-6215 is a cross-site scripting (XSS) vulnerability.