Cross-Site Scripting Vulnerability in IBM WebSphere Virtual Enterprise
CVE-2013-5425

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 November 2013

Summary

A cross-site scripting (XSS) vulnerability exists in the Administration Console of IBM WebSphere Virtual Enterprise versions prior to 6.1.1.6 (for 6.1) and 7.0.0.4 (for 7.0). This issue allows remote authenticated users to inject arbitrary web scripts or HTML into web pages through specially crafted URLs, potentially leading to unauthorized actions within user sessions. Organizations using the affected versions should prioritize patching to mitigate the risk of exploitation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.