CVE-2011-0315
IBM Websphere Application Server - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.
References (7)
Scores
EPSS
0.0048
EPSS Percentile
64.7%
Classification
CWE
CWE-79
Status
published
Affected Products (35)
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
... and 20 more
Timeline
Published
Jan 12, 2011
Tracked Since
Feb 18, 2026