{"api_version":"1","generated_at":"2026-07-23T10:21:51+00:00","cve":"CVE-2008-6105","urls":{"html":"https://cve.report/CVE-2008-6105","api":"https://cve.report/api/cve/CVE-2008-6105.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-6105","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-6105"},"summary":{"title":"CVE-2008-6105","description":"Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-02-10 22:00:02","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id?1020236","name":"http://www.securitytracker.com/id?1020236","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Workplace Input Validation Hole Permits Cross-Site Scripting and Cross-Site Request Forgery Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30433","name":"http://secunia.com/advisories/30433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Workplace Unspecified Cross-Site Scripting and Request Forgery - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29625","name":"http://www.securityfocus.com/bid/29625","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Workplace Unspecified Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PJ33180","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1PJ33180","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM PJ33180: CROSS-SITE SCRIPTING AND REQUEST FORGERY VULNERABILITIES WITH WO RKPLACE FOUND USING WEBINSPECT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-6105","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6105","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"6105","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"workplace_for_business_controls_and_reporting","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"6105","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"workplace_web_content_management","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:20:24.577Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"29625","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/29625"},{"name":"1020236","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1020236"},{"name":"PJ33180","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PJ33180"},{"name":"30433","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30433"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-06-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-08-08T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"29625","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/29625"},{"name":"1020236","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1020236"},{"name":"PJ33180","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PJ33180"},{"name":"30433","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30433"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-6105","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"29625","refsource":"BID","url":"http://www.securityfocus.com/bid/29625"},{"name":"1020236","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1020236"},{"name":"PJ33180","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1PJ33180"},{"name":"30433","refsource":"SECUNIA","url":"http://secunia.com/advisories/30433"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-6105","datePublished":"2009-02-10T21:32:00.000Z","dateReserved":"2009-02-10T00:00:00.000Z","dateUpdated":"2024-08-07T11:20:24.577Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-02-10 22:00:02","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:workplace_for_business_controls_and_reporting:2.0:*:*:*:*:*:*:*","matchCriteriaId":"88B251EC-E934-433B-98B1-DAB25DBACC7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:workplace_web_content_management:6.0:*:*:*:*:*:*:*","matchCriteriaId":"A570A362-8254-42DF-8589-DD12248F1848"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"6105","Ordinal":"1","Title":"CVE-2008-6105","CVE":"CVE-2008-6105","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"6105","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2008-6105"},{"CveYear":"2008","CveId":"6105","Ordinal":"2","NoteData":"2009-02-10","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"6105","Ordinal":"3","NoteData":"2009-08-08","Type":"Other","Title":"Modified"}]}}}