CVE-2011-2754
IBM WebSphere Portal 7.x - Cross-Site Scripting in PageBuilder2 Theme
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References (2)
Core 2
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/45106
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21503959
Scores
EPSS
0.0084
EPSS Percentile
54.2%
Details
CWE
CWE-79
Status
published
Products (3)
ibm/web_content_manager
ibm/websphere_portal
7.0.0.0
ibm/websphere_portal
7.0.0.1 (5 CPE variants)
Published
Jul 17, 2011
Tracked Since
Feb 18, 2026