Lucene search

K
cveIbmCVE-2014-3102
HistoryAug 12, 2014 - 5:01 a.m.

CVE-2014-3102

2014-08-1205:01:03
CWE-79
ibm
web.nvd.nist.gov
26
ibm
websphere portal
xss
vulnerability
remote authenticated users
nvd

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

38.0%

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Affected configurations

Nvd
Node
ibmwebsphere_portalMatch7.0.0.0
OR
ibmwebsphere_portalMatch7.0.0.1
OR
ibmwebsphere_portalMatch7.0.0.2
OR
ibmwebsphere_portalMatch8.0.0.0
VendorProductVersionCPE
ibmwebsphere_portal7.0.0.0cpe:2.3:a:ibm:websphere_portal:7.0.0.0:*:*:*:*:*:*:*
ibmwebsphere_portal7.0.0.1cpe:2.3:a:ibm:websphere_portal:7.0.0.1:*:*:*:*:*:*:*
ibmwebsphere_portal7.0.0.2cpe:2.3:a:ibm:websphere_portal:7.0.0.2:*:*:*:*:*:*:*
ibmwebsphere_portal8.0.0.0cpe:2.3:a:ibm:websphere_portal:8.0.0.0:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

38.0%

Related for CVE-2014-3102