CVE-2015-2475: XSS
Cross-site scripting (XSS) vulnerability in uddi/search/frames.aspx in the UDDI Services component in Microsoft Windows Server 2008 SP2 and BizTalk Server 2010, 2013 Gold, and 2013 R2 allows remote attackers to inject arbitrary web script or HTML via the search parameter, aka "UDDI Services Elevation of Privilege Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2475?
CVE-2015-2475 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting (XSS).
How do I fix CVE-2015-2475?
To fix CVE-2015-2475, apply the security patches provided in the Microsoft security bulletins related to this vulnerability.
Which software versions are affected by CVE-2015-2475?
CVE-2015-2475 affects Microsoft Windows Server 2008 SP2, BizTalk Server 2010, 2013 Gold, and 2013 R2.
Can CVE-2015-2475 be exploited remotely?
Yes, CVE-2015-2475 can be exploited remotely by attackers to inject arbitrary web scripts through the search parameter.
What are the potential impacts of exploiting CVE-2015-2475?
Exploitation of CVE-2015-2475 may result in unauthorized access to sensitive information or the execution of malicious scripts in the user's browser.