CVE-2015-5002
MEDIUMIBM Host On-Demand 11.0-11.0.14 - Cross-Site Scripting via Crafted URL
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0 through 11.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21973985
Scores
CVSS v3
6.1
EPSS
0.0077
EPSS Percentile
51.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (14)
ibm/host_on-demand
11.0
ibm/host_on-demand
11.0.1
ibm/host_on-demand
11.0.2
ibm/host_on-demand
11.0.3
ibm/host_on-demand
11.0.4
ibm/host_on-demand
11.0.5
ibm/host_on-demand
11.0.6
ibm/host_on-demand
11.0.7
ibm/host_on-demand
11.0.8
ibm/host_on-demand
11.0.9
... and 4 more
Published
Jan 18, 2016
Tracked Since
Feb 18, 2026