CVE-2009-4999
IBM FileNet P8 Application Engine 3.5.1 - Cross-Site Scripting via Workplace Name Field
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-016 allows remote attackers to inject arbitrary web script or HTML via the Name field.
References (2)
Core 2
Core References
Various Sources x_refsource_confirm
http://download2.boulder.ibm.com/sar/CMA/IMA/00yrk/0/readme-ae351-021.htm
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PJ34852
Scores
EPSS
0.0084
EPSS Percentile
54.2%
Details
CWE
CWE-79
Status
published
Products (1)
ibm/filenet_p8_application_engine
3.5.1 (16 CPE variants)
Published
Sep 20, 2010
Tracked Since
Feb 18, 2026