CVE-2014-6188
Description
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x before 7.5.0.3, and 8.0.x before 8.0.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21693387
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21693384
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21693381
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21693379
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | websphere_service_registry_and_repository | 6.3.0 | |
| ibm | websphere_service_registry_and_repository | 6.3.0.1 | |
| ibm | websphere_service_registry_and_repository | 6.3.0.2 | |
| ibm | websphere_service_registry_and_repository | 6.3.0.3 | |
| ibm | websphere_service_registry_and_repository | 6.3.0.4 | |
| ibm | websphere_service_registry_and_repository | 7.0.0 | |
| ibm | websphere_service_registry_and_repository | 7.0.0.1 | |
| ibm | websphere_service_registry_and_repository | 7.0.0.2 | |
| ibm | websphere_service_registry_and_repository | 7.0.0.3 | |
| ibm | websphere_service_registry_and_repository | 7.0.0.4 | |
| ibm | websphere_service_registry_and_repository | 7.0.0.5 | |
| ibm | websphere_service_registry_and_repository | 7.5.0.0 | |
| ibm | websphere_service_registry_and_repository | 7.5.0.1 | |
| ibm | websphere_service_registry_and_repository | 7.5.0.2 | |
| ibm | websphere_service_registry_and_repository | 8.0 | |
| ibm | websphere_service_registry_and_repository | 8.0.0.1 | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26727
- http://www.ibm.com/support/docview.wss?uid=swg21693379
- http://www.ibm.com/support/docview.wss?uid=swg21693381
- http://www.ibm.com/support/docview.wss?uid=swg21693384
- http://www.ibm.com/support/docview.wss?uid=swg21693387
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98553
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26727
- http://www.ibm.com/support/docview.wss?uid=swg21693379
- http://www.ibm.com/support/docview.wss?uid=swg21693381
- http://www.ibm.com/support/docview.wss?uid=swg21693384
- http://www.ibm.com/support/docview.wss?uid=swg21693387
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98553
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.