CVE-2015-4998: XSS
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4998?
CVE-2015-4998 is classified as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts or HTML.
How do I fix CVE-2015-4998?
To resolve CVE-2015-4998, upgrade IBM WebSphere Portal to a version that is patched and free from this vulnerability.
Which versions of IBM WebSphere Portal are affected by CVE-2015-4998?
CVE-2015-4998 affects IBM WebSphere Portal versions 6.1.0 through 6.1.0.6, 6.1.5 through 6.1.5.3, 7.0.0 through 7.0.0.2, and 8.0.0 before 8.0.0.1.
What type of vulnerability is CVE-2015-4998?
CVE-2015-4998 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary scripts into web pages.
Can CVE-2015-4998 be exploited remotely?
Yes, CVE-2015-4998 can be exploited remotely through crafted URLs, making it crucial to apply patches without delay.