First published: Tue Jul 14 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =6.1.0.0 | |
IBM WebSphere Portal | =6.1.0.1 | |
IBM WebSphere Portal | =6.1.0.2 | |
IBM WebSphere Portal | =6.1.0.3 | |
IBM WebSphere Portal | =6.1.0.4 | |
IBM WebSphere Portal | =6.1.0.5 | |
IBM WebSphere Portal | =6.1.0.6 | |
IBM WebSphere Portal | =6.1.5.0 | |
IBM WebSphere Portal | =6.1.5.1 | |
IBM WebSphere Portal | =6.1.5.2 | |
IBM WebSphere Portal | =6.1.5.3 | |
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1917 is classified with a medium severity level, indicating a moderate risk to affected systems.
To mitigate CVE-2015-1917, apply the latest patches and updates provided by IBM for affected versions of WebSphere Portal.
CVE-2015-1917 affects multiple versions of IBM WebSphere Portal, specifically versions 6.1.0 through 6.1.0.6, 6.1.5 through 6.1.5.3, 7.0.0 through 7.0.0.2, 8.0.0 before 8.0.0.1, and 8.5.0 before CF06.
CVE-2015-1917 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Yes, CVE-2015-1917 can be exploited by remote attackers, making it crucial for affected users to address the vulnerability promptly.