Multiple cross-site scripting (XSS) vulnerabilities in IBM Connections Portlets 4.x before 4.5.1 FP1 for IBM WebSphere Portal 7.0.0.2 and 8.0.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2014-02-14T13:10:30.623
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | connections_portlets | 4.0 | Yes |
Application | ibm | connections_portlets | 4.5 | Yes |
Application | ibm | connections_portlets | 4.5.1 | Yes |
Application | ibm | websphere_portal | 7.0.0.2 | No |
Application | ibm | websphere_portal | 8.0.0.1 | No |