CVE-2011-2754

IBM WebSphere Portal 7.x - Cross-Site Scripting in PageBuilder2 Theme

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

References (2)

Core 2
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45106
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21503959

Scores

EPSS 0.0084
EPSS Percentile 53.7%

Details

CWE
CWE-79
Status published
Products (3)
ibm/web_content_manager
ibm/websphere_portal 7.0.0.0
ibm/websphere_portal 7.0.0.1 (5 CPE variants)
Published Jul 17, 2011
Tracked Since Feb 18, 2026