CVE-2014-6196 Information

Description

Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1 as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF) allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration leading to improper construction of a response page by an application.

Reference

http://secunia.com/advisories/59546 http://www-01.ibm.com/support/docview.wss?uid=swg1LO82672 http://www-01.ibm.com/support/docview.wss?uid=swg1LO82673 http://www-01.ibm.com/support/docview.wss?uid=swg1LO82674 http://www-01.ibm.com/support/docview.wss?uid=swg1LO82675 http://www-01.ibm.com/support/docview.wss?uid=swg1LO82676 http://www-01.ibm.com/support/docview.wss?uid=swg21690018 https://exchange.xforce.ibmcloud.com/vulnerabilities/98608

Share on: