Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.
2013-12-17T15:21:28.683
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | websphere_service_registry_and_repository | 7.5 | No |
Application | ibm | websphere_service_registry_and_repository | 7.5.0.1 | No |
Application | ibm | websphere_service_registry_and_repository | 7.5.0.2 | Yes |
Application | ibm | websphere_service_registry_and_repository | 7.5.0.3 | Yes |
Application | ibm | websphere_service_registry_and_repository | 8.0.0 | Yes |
Application | ibm | websphere_service_registry_and_repository | 8.0.0.1 | Yes |
Application | ibm | websphere_service_registry_and_repository | 8.0.0.2 | Yes |