CVE-2011-4887
Published on: 09/11/2014 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:23:11 PM UTC
Certain versions of Securesphere Web Application Firewall from Imperva contain the following vulnerability:
Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to inject arbitrary web script or HTML via the username field.
- CVE-2011-4887 has been assigned by
[email protected] to track the vulnerability
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Imperva SecureSphere persistent cross-site scripting vulnerability | Dell SecureWorks | www.secureworks.com text/html |
![]() |
Security Advisory SA48086 - SecureSphere Web Application Firewall Username Script Insertion Vulnerability - Secunia | web.archive.org text/html |
![]() |
SecureSphere Web Application Firewall Username HTML Injection Vulnerability | cve.report (archive) text/html |
![]() |
Imperva Security Response for CVE-2011-4887 | Patch Vendor Advisory www.imperva.com text/html |
![]() |
No Description Provided | osvdb.org Inactive LinkNot Archived |
![]() |
IBM X-Force Exchange | exchange.xforce.ibmcloud.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Imperva | Securesphere Web Application Firewall | 9.0 | All | All | All |
Application | Imperva | Securesphere Web Application Firewall | 9.0 | All | All | All |
- cpe:2.3:a:imperva:securesphere_web_application_firewall:9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:imperva:securesphere_web_application_firewall:9.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE