CVE-2015-0195: XSS
Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0195?
CVE-2015-0195 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-0195?
To fix CVE-2015-0195, update IBM Content Template Catalog to version 4.1.4 or later, or version 4.3.1 or later for affected installations.
What systems are affected by CVE-2015-0195?
CVE-2015-0195 affects IBM Content Template Catalog versions prior to 4.1.4 and 4.3.1, and WebSphere Portal versions 8.0.x and 8.5.x.
What type of vulnerability is CVE-2015-0195?
CVE-2015-0195 is a cross-site scripting (XSS) vulnerability.
Can CVE-2015-0195 be exploited remotely?
Yes, remote attackers can exploit CVE-2015-0195 by injecting arbitrary web script or HTML through a crafted URL.