Cross-Site Scripting Vulnerability in IBM WebSphere Service Registry and Repository
CVE-2014-6180
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 24 December 2014
What is CVE-2014-6180?
A Cross-Site Scripting (XSS) vulnerability exists in the Web UI of IBM WebSphere Service Registry and Repository, which allows remote authenticated users to inject arbitrary web scripts or HTML. This injection occurs via the HTTP User-Agent header, potentially compromising the security of affected web applications by enabling attackers to execute malicious scripts in the context of authenticated users' sessions.