First published: Sat Oct 03 2015(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Template Catalog | <=4.1.3 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 | |
IBM Content Template Catalog | <=4.3 | |
IBM WebSphere Portal | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0195 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2015-0195, update IBM Content Template Catalog to version 4.1.4 or later, or version 4.3.1 or later for affected installations.
CVE-2015-0195 affects IBM Content Template Catalog versions prior to 4.1.4 and 4.3.1, and WebSphere Portal versions 8.0.x and 8.5.x.
CVE-2015-0195 is a cross-site scripting (XSS) vulnerability.
Yes, remote attackers can exploit CVE-2015-0195 by injecting arbitrary web script or HTML through a crafted URL.