CVE-2010-4220

IBM WebSphere Application Server 7.0 - Cross-Site Scripting in Administrative Console

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM11777
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41722

Scores

EPSS 0.0166
EPSS Percentile 74.1%

Details

CWE
CWE-79
Status published
Products (13)
ibm/websphere_application_server 7.0
ibm/websphere_application_server 7.0.0.1
ibm/websphere_application_server 7.0.0.2
ibm/websphere_application_server 7.0.0.3
ibm/websphere_application_server 7.0.0.4
ibm/websphere_application_server 7.0.0.5
ibm/websphere_application_server 7.0.0.6
ibm/websphere_application_server 7.0.0.7
ibm/websphere_application_server 7.0.0.8
ibm/websphere_application_server 7.0.0.9
... and 3 more
Published Nov 09, 2010
Tracked Since Feb 18, 2026