CVE-2015-4993
MEDIUMIBM Websphere Portal - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.
References (4)
Scores
CVSS v3
6.1
EPSS
0.0023
EPSS Percentile
45.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (17)
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
ibm/websphere_portal
... and 2 more
Timeline
Published
Dec 21, 2015
Tracked Since
Feb 18, 2026