Lucene search

K
cveMitreCVE-2011-1357
HistoryAug 11, 2011 - 10:55 p.m.

CVE-2011-1357

2011-08-1122:55:00
CWE-79
mitre
web.nvd.nist.gov
20
cve-2011-1357
xss
web ui
ibm
websphere
service
registry
repository
wsrr
vulnerability
remote attackers
http header

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

46.8%

Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

Affected configurations

Nvd
Node
ibmwebsphere_service_registry_and_repositoryMatch6.3.0
OR
ibmwebsphere_service_registry_and_repositoryMatch6.3.0.1
OR
ibmwebsphere_service_registry_and_repositoryMatch6.3.0.2
OR
ibmwebsphere_service_registry_and_repositoryMatch6.3.0.3
OR
ibmwebsphere_service_registry_and_repositoryMatch6.3.0.4
OR
ibmwebsphere_service_registry_and_repositoryMatch7.0.0
OR
ibmwebsphere_service_registry_and_repositoryMatch7.0.0.1
OR
ibmwebsphere_service_registry_and_repositoryMatch7.0.0.2
OR
ibmwebsphere_service_registry_and_repositoryMatch7.0.0.3
OR
ibmwebsphere_service_registry_and_repositoryMatch7.0.0.4
OR
ibmwebsphere_service_registry_and_repositoryMatch7.5
VendorProductVersionCPE
ibmwebsphere_service_registry_and_repository6.3.0cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository6.3.0.1cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.1:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository6.3.0.2cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.2:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository6.3.0.3cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.3:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository6.3.0.4cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.4:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository7.0.0cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository7.0.0.1cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.1:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository7.0.0.2cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.2:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository7.0.0.3cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.3:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository7.0.0.4cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

46.8%

Related for CVE-2011-1357