Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration, leading to improper construction of a response page by an application.
References 8 Total
- www-01.ibm.com: LO82674 vendor-advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21690018
- www-01.ibm.com: LO82675 vendor-advisory
- exchange.xforce.ibmcloud.com: ibm-wef-cve20146196-xss(98608) vdb-entry
- www-01.ibm.com: LO82672 vendor-advisory
- www-01.ibm.com: LO82676 vendor-advisory
- secunia.com: 59546 third-party-advisory
- www-01.ibm.com: LO82673 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- www-01.ibm.com: LO82674 vendor-advisoryx_transferred
- http://www-01.ibm.com/support/docview.wss?uid=swg21690018 x_transferred
- www-01.ibm.com: LO82675 vendor-advisoryx_transferred
- exchange.xforce.ibmcloud.com: ibm-wef-cve20146196-xss(98608) vdb-entryx_transferred
- www-01.ibm.com: LO82672 vendor-advisoryx_transferred
- www-01.ibm.com: LO82676 vendor-advisoryx_transferred
- secunia.com: 59546 third-party-advisoryx_transferred
- www-01.ibm.com: LO82673 vendor-advisoryx_transferred