{"api_version":"1","generated_at":"2026-07-23T22:42:15+00:00","cve":"CVE-2011-4887","urls":{"html":"https://cve.report/CVE-2011-4887","api":"https://cve.report/api/cve/CVE-2011-4887.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-4887","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-4887"},"summary":{"title":"CVE-2011-4887","description":"Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to inject arbitrary web script or HTML via the username field.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-09-11 14:16:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/48086","name":"http://secunia.com/advisories/48086","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA48086 - SecureSphere Web Application Firewall Username Script Insertion Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-002/","name":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-002/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Imperva SecureSphere persistent cross-site scripting vulnerability | Dell SecureWorks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/79338","name":"http://osvdb.org/79338","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.imperva.com/Services/adc_advisories_response_secureworks_CVE_2011_4887","name":"http://www.imperva.com/Services/adc_advisories_response_secureworks_CVE_2011_4887","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Imperva Security Response for CVE-2011-4887","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73264","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73264","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/52064","name":"http://www.securityfocus.com/bid/52064","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecureSphere Web Application Firewall Username HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-4887","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4887","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"4887","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"imperva","cpe5":"securesphere_web_application_firewall","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:16:35.130Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-002/"},{"name":"securesphere-unspec-xss(73264)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73264"},{"name":"52064","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/52064"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.imperva.com/Services/adc_advisories_response_secureworks_CVE_2011_4887"},{"name":"79338","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/79338"},{"name":"48086","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/48086"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-02-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to inject arbitrary web script or HTML via the username field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-002/"},{"name":"securesphere-unspec-xss(73264)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73264"},{"name":"52064","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/52064"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.imperva.com/Services/adc_advisories_response_secureworks_CVE_2011_4887"},{"name":"79338","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/79338"},{"name":"48086","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/48086"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-4887","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to inject arbitrary web script or HTML via the username field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-002/","refsource":"MISC","url":"http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2012-002/"},{"name":"securesphere-unspec-xss(73264)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73264"},{"name":"52064","refsource":"BID","url":"http://www.securityfocus.com/bid/52064"},{"name":"http://www.imperva.com/Services/adc_advisories_response_secureworks_CVE_2011_4887","refsource":"CONFIRM","url":"http://www.imperva.com/Services/adc_advisories_response_secureworks_CVE_2011_4887"},{"name":"79338","refsource":"OSVDB","url":"http://osvdb.org/79338"},{"name":"48086","refsource":"SECUNIA","url":"http://secunia.com/advisories/48086"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-4887","datePublished":"2014-09-11T14:00:00.000Z","dateReserved":"2011-12-21T00:00:00.000Z","dateUpdated":"2024-08-07T00:16:35.130Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-09-11 14:16:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:imperva:securesphere_web_application_firewall:9.0:*:*:*:*:*:*:*","matchCriteriaId":"D311E127-DC16-4C27-B830-AB8406C7CBC1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"4887","Ordinal":"1","Title":"CVE-2011-4887","CVE":"CVE-2011-4887","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"4887","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to inject arbitrary web script or HTML via the username field.","Type":"Description","Title":"CVE-2011-4887"},{"CveYear":"2011","CveId":"4887","Ordinal":"2","NoteData":"2014-09-11","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"4887","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}