CVE-2015-1908: XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1908?
CVE-2015-1908 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-1908?
To fix CVE-2015-1908, update your IBM WebSphere Portal to a fixed version that addresses the XSS vulnerability.
Which versions of IBM WebSphere Portal are affected by CVE-2015-1908?
CVE-2015-1908 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6, 6.1.5 through 6.1.5.3, 7.0.0 through 7.0.0.2, and 8.0.0 before 8.0.0.1.
What type of vulnerability is CVE-2015-1908?
CVE-2015-1908 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts.
Can CVE-2015-1908 be exploited remotely?
Yes, CVE-2015-1908 can be exploited remotely by attackers to execute malicious scripts in the context of the user's session.