VulnerabilityModified
CVE-2009-4152
Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.x before 6.1.0.3 allows remote attackers to inject arbitrary web script or HTML via the people picker tag.
MEDIUM 4.3EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.x before 6.1.0.3 allows remote attackers to inject arbitrary web script or HTML via the people picker tag.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/websphere portal
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/37526Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK93429
- http://www-01.ibm.com/support/docview.wss?uid=swg27014411
- http://www.securityfocus.com/bid/37159
- http://www.vupen.com/english/advisories/2009/3367Vendor Advisory
- http://secunia.com/advisories/37526Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK93429
- http://www-01.ibm.com/support/docview.wss?uid=swg27014411
- http://www.securityfocus.com/bid/37159
- http://www.vupen.com/english/advisories/2009/3367Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.