CVE-2011-1362

Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
ibmwebsphere_application_server
6.1
ibmwebsphere_application_server
6.1.0
ibmwebsphere_application_server
6.1.0.0
ibmwebsphere_application_server
6.1.0.1
ibmwebsphere_application_server
6.1.0.2
ibmwebsphere_application_server
6.1.0.3
ibmwebsphere_application_server
6.1.0.5
ibmwebsphere_application_server
6.1.0.7
ibmwebsphere_application_server
6.1.0.9
ibmwebsphere_application_server
6.1.0.11
ibmwebsphere_application_server
6.1.0.12
ibmwebsphere_application_server
6.1.0.15
ibmwebsphere_application_server
6.1.0.17
ibmwebsphere_application_server
6.1.0.19
ibmwebsphere_application_server
6.1.0.21
ibmwebsphere_application_server
6.1.0.23
ibmwebsphere_application_server
6.1.0.25
ibmwebsphere_application_server
6.1.0.27
ibmwebsphere_application_server
6.1.0.29
ibmwebsphere_application_server
6.1.0.31
ibmwebsphere_application_server
6.1.0.33
ibmwebsphere_application_server
6.1.0.35
ibmwebsphere_application_server
6.1.0.37
ibmwebsphere_application_server
6.1.0.39
ibmwebsphere_application_server
6.1.1
ibmwebsphere_application_server
6.1.3
ibmwebsphere_application_server
6.1.5
ibmwebsphere_application_server
6.1.6
ibmwebsphere_application_server
6.1.7
ibmwebsphere_application_server
6.1.13
ibmwebsphere_application_server
6.1.14
ibmwebsphere_application_server
7.0
ibmwebsphere_application_server
7.0.0.1
ibmwebsphere_application_server
7.0.0.2
ibmwebsphere_application_server
7.0.0.3
ibmwebsphere_application_server
7.0.0.4
ibmwebsphere_application_server
7.0.0.5
ibmwebsphere_application_server
7.0.0.6
ibmwebsphere_application_server
7.0.0.7
ibmwebsphere_application_server
7.0.0.8
ibmwebsphere_application_server
7.0.0.9
ibmwebsphere_application_server
7.0.0.11
ibmwebsphere_application_server
7.0.0.13
ibmwebsphere_application_server
7.0.0.15
ibmwebsphere_application_server
7.0.0.17
𝑥
= Vulnerable software versions