CVE-2010-2325
IBM Websphere Application Server < 7.0.0.10 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."
Scores
EPSS
0.0025
EPSS Percentile
47.9%
Classification
CWE
CWE-79
Status
published
Affected Products (12)
ibm/websphere_application_server
< 7.0.0.10
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
n/a/n/a
Timeline
Published
Jun 18, 2010
Tracked Since
Feb 18, 2026