The dojox/form/resources/fileuploader.swf, dojox/form/resources/uploader.swf, dojox/av/resources/audio.swf, and dojox/av/resources/video.swf files exhibit an cross-site scripting (XSS) vulnerability. Any web application using the IBM Dojo Toolkit and providing those files might be subject to this vulnerability.
CVEID: CVE-2014-8917**
DESCRIPTION:** IBM Dojo Toolkit is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victimโs Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victimโs cookie-based authentication credentials.
CVSS Base Score: 4.3
CVSS Temporal Score: See _<https://exchange.xforce.ibmcloud.com/vulnerabilities/99303>_ for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Dojo 1.4 and 1.5 packaged with Rational Software Architect and Rational Software Architect for WebSphere Software 8.0.x and 8.5.x
Update the Dojo runtime provided by the product to address this vulnerability:
For Dojo version 1.4 included with IBM Rational Software Architect and Rational Software Architect for WebSphere Software Version 8.0.x or Version 8.5.x
1. On the Select Fixes page, select interim fix: Rational-dojo141-CVE-2014-8917-ifix (Fix for the CVE-2014-8917 vulnerability in Dojo)
Product | VRMF | Remediation/Fix |
---|---|---|
Rational Software Architect |
Rational Software Architect for WebSphere Software| 8.0 to 8.0.4.2Ifix1
8.5 to 8.5.5.3| Rational-dojo141-CVE-2014-8917-ifix
Rational-dojo15-CVE-2014-8917-ifix
Instructions to download and install the update from the compressed files
1. Locate your existing Dojo installation folder in your projects; for example; Project/WebContent/dojo. To find your specific location, follow these instructions:
1.Right-click on your Web project and select Properties
2.Click on the Dojo Toolkit page
3.Look at the path specified in the Dojo Project Setup Summary section 2. Backup your existing Dojo installation by renaming the folder to; for example; Project/WebContent/dojo.bak/
3. Recreate the original Dojo installation folder; for example, Project/WebContent/dojo/
4. Download the updated Dojo runtime from the link listed in the Remediation**/Fix** in above table and save it to the Dojo installation folder from step 3
5. Extract the compressed Dojo archive into your Dojo installation folder
None