CVE-2016-2925

EUVD-2016-3998
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
ibmwebsphere_portal
6.1.0.0
ibmwebsphere_portal
6.1.0.1
ibmwebsphere_portal
6.1.0.2
ibmwebsphere_portal
6.1.0.3
ibmwebsphere_portal
6.1.0.4
ibmwebsphere_portal
6.1.0.5
ibmwebsphere_portal
6.1.0.6
ibmwebsphere_portal
6.1.5.0
ibmwebsphere_portal
6.1.5.1
ibmwebsphere_portal
6.1.5.2
ibmwebsphere_portal
6.1.5.3
ibmwebsphere_portal
7.0.0.0
ibmwebsphere_portal
7.0.0.1
ibmwebsphere_portal
7.0.0.2
ibmwebsphere_portal
8.0.0.0
ibmwebsphere_portal
8.0.0.1
ibmwebsphere_portal
8.5.0.0
𝑥
= Vulnerable software versions