[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-6196Date: (C)2014-12-04   (M)2023-12-22


Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration, leading to improper construction of a response page by an application.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-59546
LO82672
LO82673
LO82674
LO82675
LO82676
http://www-01.ibm.com/support/docview.wss?uid=swg21690018
ibm-wef-cve20146196-xss(98608)

CPE    14
cpe:/a:ibm:web_experience_factory:6.1.5
cpe:/a:ibm:web_experience_factory:8.0.0
cpe:/a:ibm:web_experience_factory:8.0
cpe:/a:ibm:websphere_dashboard_framework:-
...
CWE    1
CWE-79

© SecPod Technologies