CVE-2010-2325

IBM Websphere Application Server < 7.0.0.10 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."

Scores

EPSS 0.0025
EPSS Percentile 47.9%

Classification

CWE
CWE-79
Status published

Affected Products (12)

ibm/websphere_application_server < 7.0.0.10
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
n/a/n/a

Timeline

Published Jun 18, 2010
Tracked Since Feb 18, 2026