CVE-2015-4993

MEDIUM

IBM Websphere Portal - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.

References (4)

Core 4
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI47516
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21970176
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/78609
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034284

Scores

CVSS v3 6.1
EPSS 0.0143
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (17)
ibm/websphere_portal 6.1.0.0
ibm/websphere_portal 6.1.0.1
ibm/websphere_portal 6.1.0.2
ibm/websphere_portal 6.1.0.3
ibm/websphere_portal 6.1.0.4
ibm/websphere_portal 6.1.0.5
ibm/websphere_portal 6.1.0.6
ibm/websphere_portal 6.1.5.0
ibm/websphere_portal 6.1.5.1
ibm/websphere_portal 6.1.5.2
... and 7 more
Published Dec 21, 2015
Tracked Since Feb 18, 2026