Cross-Site Scripting Vulnerability in IBM WebSphere DataPower XC10 Appliance
CVE-2014-6163
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 11 December 2014
What is CVE-2014-6163?
The vulnerability in the IBM WebSphere DataPower XC10 appliance affects versions 2.1 and 2.5 before FP4, allowing remote authenticated users to execute arbitrary web scripts or HTML through carefully crafted URLs, which could lead to unauthorized actions on behalf of the users.