CVE-2017-1189

IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
ibmwebsphere_portal
6.1.0.0
ibmwebsphere_portal
6.1.0.1
ibmwebsphere_portal
6.1.0.2
ibmwebsphere_portal
6.1.0.3
ibmwebsphere_portal
6.1.0.4
ibmwebsphere_portal
6.1.0.5
ibmwebsphere_portal
6.1.0.6
ibmwebsphere_portal
6.1.5.0
ibmwebsphere_portal
6.1.5.1
ibmwebsphere_portal
6.1.5.2
ibmwebsphere_portal
6.1.5.3
ibmwebsphere_portal
7.0.0.0
ibmwebsphere_portal
7.0.0.0:cf001
ibmwebsphere_portal
7.0.0.1
ibmwebsphere_portal
7.0.0.1:cf002
ibmwebsphere_portal
7.0.0.1:cf003
ibmwebsphere_portal
7.0.0.1:cf004
ibmwebsphere_portal
7.0.0.1:cf005
ibmwebsphere_portal
7.0.0.1:cf006
ibmwebsphere_portal
7.0.0.1:cf007
ibmwebsphere_portal
7.0.0.1:cf008
ibmwebsphere_portal
7.0.0.1:cf009
ibmwebsphere_portal
7.0.0.1:cf010
ibmwebsphere_portal
7.0.0.1:cf019
ibmwebsphere_portal
7.0.0.2
ibmwebsphere_portal
7.0.0.2:cf011
ibmwebsphere_portal
7.0.0.2:cf012
ibmwebsphere_portal
7.0.0.2:cf013
ibmwebsphere_portal
7.0.0.2:cf014
ibmwebsphere_portal
7.0.0.2:cf015
ibmwebsphere_portal
7.0.0.2:cf016
ibmwebsphere_portal
7.0.0.2:cf017
ibmwebsphere_portal
7.0.0.2:cf018
ibmwebsphere_portal
7.0.0.2:cf019
ibmwebsphere_portal
7.0.0.2:cf020
ibmwebsphere_portal
7.0.0.2:cf021
ibmwebsphere_portal
7.0.0.2:cf022
ibmwebsphere_portal
7.0.0.2:cf23
ibmwebsphere_portal
7.0.0.2:cf24
ibmwebsphere_portal
7.0.0.2:cf25
ibmwebsphere_portal
7.0.0.2:cf26
ibmwebsphere_portal
7.0.0.2:cf27
ibmwebsphere_portal
8.0
ibmwebsphere_portal
8.0.0.0
ibmwebsphere_portal
8.0.0.0:cf01
ibmwebsphere_portal
8.0.0.0:cf02
ibmwebsphere_portal
8.0.0.0:cf03
ibmwebsphere_portal
8.0.0.0:cf04
ibmwebsphere_portal
8.0.0.0:cf05
ibmwebsphere_portal
8.0.0.1
ibmwebsphere_portal
8.0.0.1:cf04
ibmwebsphere_portal
8.0.0.1:cf05
ibmwebsphere_portal
8.0.0.1:cf06
ibmwebsphere_portal
8.0.0.1:cf07
ibmwebsphere_portal
8.0.0.1:cf08
ibmwebsphere_portal
8.0.0.1:cf09
ibmwebsphere_portal
8.0.0.1:cf12
𝑥
= Vulnerable software versions