CVE-2014-3057

Cross-site scripting (XSS) vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
ibmwebsphere_portal
7.0.0.0
ibmwebsphere_portal
7.0.0.1:cf003
ibmwebsphere_portal
7.0.0.1:cf004
ibmwebsphere_portal
7.0.0.1:cf005
ibmwebsphere_portal
7.0.0.1:cf006
ibmwebsphere_portal
7.0.0.1:cf007
ibmwebsphere_portal
7.0.0.1:cf008
ibmwebsphere_portal
7.0.0.1:cf009
ibmwebsphere_portal
7.0.0.1:cf010
ibmwebsphere_portal
7.0.0.1:cf019
ibmwebsphere_portal
7.0.0.2
ibmwebsphere_portal
7.0.0.2
ibmwebsphere_portal
7.0.0.2:cf011
ibmwebsphere_portal
7.0.0.2:cf012
ibmwebsphere_portal
7.0.0.2:cf013
ibmwebsphere_portal
7.0.0.2:cf014
ibmwebsphere_portal
7.0.0.2:cf015
ibmwebsphere_portal
7.0.0.2:cf016
ibmwebsphere_portal
7.0.0.2:cf017
ibmwebsphere_portal
7.0.0.2:cf018
ibmwebsphere_portal
7.0.0.2:cf019
ibmwebsphere_portal
7.0.0.2:cf020
ibmwebsphere_portal
7.0.0.2:cf021
ibmwebsphere_portal
7.0.0.2:cf022
ibmwebsphere_portal
7.0.0.2:cf23
ibmwebsphere_portal
7.0.0.2:cf24
ibmwebsphere_portal
7.0.0.2:cf25
ibmwebsphere_portal
7.0.0.2:cf26
ibmwebsphere_portal
7.0.0.2:cf27
ibmwebsphere_portal
8.0.0.0
ibmwebsphere_portal
8.0.0.0:cf01
ibmwebsphere_portal
8.0.0.0:cf02
ibmwebsphere_portal
8.0.0.0:cf03
ibmwebsphere_portal
8.0.0.0:cf04
ibmwebsphere_portal
8.0.0.0:cf05
ibmwebsphere_portal
8.0.0.1
ibmwebsphere_portal
8.0.0.1:cf04
ibmwebsphere_portal
8.0.0.1:cf05
ibmwebsphere_portal
8.0.0.1:cf06
ibmwebsphere_portal
8.0.0.1:cf07
ibmwebsphere_portal
8.0.0.1:cf08
ibmwebsphere_portal
8.0.0.1:cf09
ibmwebsphere_portal
8.0.0.1:cf12
ibmwebsphere_portal_unified_task_list_portlet
6.0.1
𝑥
= Vulnerable software versions