First published: Fri Mar 13 2015(Updated: )
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM WebSphere Portal | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0139 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2015-0139, upgrade IBM WebSphere Portal to the latest version that includes the necessary patches.
CVE-2015-0139 affects remote authenticated users of IBM WebSphere Portal versions 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05.
CVE-2015-0139 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
The potential impacts of CVE-2015-0139 include unauthorized access to user information and the execution of malicious scripts in a user's browser.