IBM WebSphere Portal Cross Site Scripting and Unspecified Security Vulnerabilities
BID:37159
Info
IBM WebSphere Portal Cross Site Scripting and Unspecified Security Vulnerabilities
| Bugtraq ID: | 37159 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2009 12:00AM |
| Updated: | Dec 01 2009 03:24PM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Portal 6.1 .2 IBM Websphere Portal 6.1 |
| Not Vulnerable: |
IBM Websphere Portal 6.1 .3 |
Discussion
IBM WebSphere Portal Cross Site Scripting and Unspecified Security Vulnerabilities
IBM WebSphere Portal is prone to these security vulnerabilities:
- A cross-site scripting vulnerability.
- An unspecified security vulnerability related to 'XMLACCESS'.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials. The impact of the other issue is unknown.
Versions prior to IBM WebSphere Portal 6.1.0.3 are vulnerable.
IBM WebSphere Portal is prone to these security vulnerabilities:
- A cross-site scripting vulnerability.
- An unspecified security vulnerability related to 'XMLACCESS'.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials. The impact of the other issue is unknown.
Versions prior to IBM WebSphere Portal 6.1.0.3 are vulnerable.
Exploit / POC
IBM WebSphere Portal Cross Site Scripting and Unspecified Security Vulnerabilities
An attacker may exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker may entice an unsuspecting victim to follow a malicious URI.
An attacker may exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker may entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
IBM WebSphere Portal Cross Site Scripting and Unspecified Security Vulnerabilities
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
IBM WebSphere Portal Cross Site Scripting and Unspecified Security Vulnerabilities
References:
References: