CVE-2011-1362
IBM WebSphere Application Server <6.1.0.41, <7.0.0.19 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 and 7.0 before 7.0.0.19 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1308.
References (4)
Scores
EPSS
0.0023
EPSS Percentile
45.4%
Classification
CWE
CWE-79
Status
published
Affected Products (46)
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
ibm/websphere_application_server
... and 31 more
Timeline
Published
Jan 15, 2012
Tracked Since
Feb 18, 2026