CVE-2015-2944
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1)…
Does this matter?
Lower severity and a low EPSS score (6.30%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 6.30% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/sling api · apache/sling servlets post
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN61328139/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000069Vendor Advisory
- http://www.securityfocus.com/bid/74839
- https://issues.apache.org/jira/browse/SLING-2082Exploit, Vendor Advisory
- https://lists.apache.org/thread.html/r04237d561f3e5bced0a26287454450a34275162aa6b1dbae1b707b31%40%3Cdev.sling.apache.org%3E
- https://lists.apache.org/thread.html/r4f41dd891a52133abdbf7f74ad1dde80c46f157c1f1cf8c23ba60a70%40%3Cdev.sling.apache.org%3E
- https://lists.apache.org/thread.html/r93d68359eb0ea8c0f26d71ca3998143f99209a24db7b4dacfc688cea%40%3Cdev.sling.apache.org%3E
- https://lists.apache.org/thread.html/rd2a352858630721e7b1655bbdf85e692d6156fcfe68109e12b017b16%40%3Cdev.sling.apache.org%3E
- http://jvn.jp/en/jp/JVN61328139/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000069Vendor Advisory
- http://www.securityfocus.com/bid/74839
- https://issues.apache.org/jira/browse/SLING-2082Exploit, Vendor Advisory
- https://lists.apache.org/thread.html/r04237d561f3e5bced0a26287454450a34275162aa6b1dbae1b707b31%40%3Cdev.sling.apache.org%3E
- https://lists.apache.org/thread.html/r4f41dd891a52133abdbf7f74ad1dde80c46f157c1f1cf8c23ba60a70%40%3Cdev.sling.apache.org%3E
- https://lists.apache.org/thread.html/r93d68359eb0ea8c0f26d71ca3998143f99209a24db7b4dacfc688cea%40%3Cdev.sling.apache.org%3E
- https://lists.apache.org/thread.html/rd2a352858630721e7b1655bbdf85e692d6156fcfe68109e12b017b16%40%3Cdev.sling.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.