Korean
<< Back
VID 22774
Severity 20
Port 8880, ...
Protocol TCP
Class WWW
Detailed Description IBM WebSphere Application Server 7.0 prior to Fix Pack 43 is running on the remote host. It is, therefore, affected by multiple cross-site scripting (XSS) vulnerabilities in the Admin Console due to a failure to validate input before returning it to users. An authenticated, remote attacker can exploit these, via a specially crafted URL, to execute arbitrary script code in a user's browser session within the security context of the hosting website.

* Note: This check solely relied on the banner of the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www-01.ibm.com/support/docview.wss?uid=swg21992315
http://www-01.ibm.com/support/docview.wss?uid=swg21997743
http://www-01.ibm.com/support/docview.wss?uid=swg24043318

* Platforms Affected:
IBM WebSphere Application Server versions 7.0 prior to 7.0 Fix Pack 43
Recommendation Upgrade to the latest version of IBM WebSphere Application Server 7.0.0.43 or later, available from the IBM Support & downloads Web site at http://www-01.ibm.com/support/docview.wss?uid=swg21992315
Alternatively, apply Interim Fixes PI70169 at http://www-01.ibm.com/support/docview.wss?uid=swg24043126, PI70627 at http://www-01.ibm.com/support/docview.wss?uid=swg24043120, PI73367 at http://www-01.ibm.com/support/docview.wss?uid=swg24043318
Related URL CVE-2016-8934,CVE-2017-1121 (CVE)
Related URL 95154,96164 (SecurityFocus)
Related URL (ISS)