CVE-2017-1189
07.09.2017, 16:29
IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558.
Vendor | Product | Version |
---|---|---|
ibm | websphere_portal | 6.1.0.0 |
ibm | websphere_portal | 6.1.0.1 |
ibm | websphere_portal | 6.1.0.2 |
ibm | websphere_portal | 6.1.0.3 |
ibm | websphere_portal | 6.1.0.4 |
ibm | websphere_portal | 6.1.0.5 |
ibm | websphere_portal | 6.1.0.6 |
ibm | websphere_portal | 6.1.5.0 |
ibm | websphere_portal | 6.1.5.1 |
ibm | websphere_portal | 6.1.5.2 |
ibm | websphere_portal | 6.1.5.3 |
ibm | websphere_portal | 7.0.0.0 |
ibm | websphere_portal | 7.0.0.0:cf001 |
ibm | websphere_portal | 7.0.0.1 |
ibm | websphere_portal | 7.0.0.1:cf002 |
ibm | websphere_portal | 7.0.0.1:cf003 |
ibm | websphere_portal | 7.0.0.1:cf004 |
ibm | websphere_portal | 7.0.0.1:cf005 |
ibm | websphere_portal | 7.0.0.1:cf006 |
ibm | websphere_portal | 7.0.0.1:cf007 |
ibm | websphere_portal | 7.0.0.1:cf008 |
ibm | websphere_portal | 7.0.0.1:cf009 |
ibm | websphere_portal | 7.0.0.1:cf010 |
ibm | websphere_portal | 7.0.0.1:cf019 |
ibm | websphere_portal | 7.0.0.2 |
ibm | websphere_portal | 7.0.0.2:cf011 |
ibm | websphere_portal | 7.0.0.2:cf012 |
ibm | websphere_portal | 7.0.0.2:cf013 |
ibm | websphere_portal | 7.0.0.2:cf014 |
ibm | websphere_portal | 7.0.0.2:cf015 |
ibm | websphere_portal | 7.0.0.2:cf016 |
ibm | websphere_portal | 7.0.0.2:cf017 |
ibm | websphere_portal | 7.0.0.2:cf018 |
ibm | websphere_portal | 7.0.0.2:cf019 |
ibm | websphere_portal | 7.0.0.2:cf020 |
ibm | websphere_portal | 7.0.0.2:cf021 |
ibm | websphere_portal | 7.0.0.2:cf022 |
ibm | websphere_portal | 7.0.0.2:cf23 |
ibm | websphere_portal | 7.0.0.2:cf24 |
ibm | websphere_portal | 7.0.0.2:cf25 |
ibm | websphere_portal | 7.0.0.2:cf26 |
ibm | websphere_portal | 7.0.0.2:cf27 |
ibm | websphere_portal | 8.0 |
ibm | websphere_portal | 8.0.0.0 |
ibm | websphere_portal | 8.0.0.0:cf01 |
ibm | websphere_portal | 8.0.0.0:cf02 |
ibm | websphere_portal | 8.0.0.0:cf03 |
ibm | websphere_portal | 8.0.0.0:cf04 |
ibm | websphere_portal | 8.0.0.0:cf05 |
ibm | websphere_portal | 8.0.0.1 |
ibm | websphere_portal | 8.0.0.1:cf04 |
ibm | websphere_portal | 8.0.0.1:cf05 |
ibm | websphere_portal | 8.0.0.1:cf06 |
ibm | websphere_portal | 8.0.0.1:cf07 |
ibm | websphere_portal | 8.0.0.1:cf08 |
ibm | websphere_portal | 8.0.0.1:cf09 |
ibm | websphere_portal | 8.0.0.1:cf12 |
𝑥
= Vulnerable software versions
References