CVE-2010-0768
published 2010-04-01CVE-2010-0768: Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.64%
74.0th percentile
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | <= 6.0.2.39 | — |
| ibm | websphere_application_server | <= 6.1.0.29 | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2010-3567 OpenJDK ICU Opentype layout engine crash (6963285)
bugzilla·2010-10-12·CVSS 10.0
CVE-2010-3567 [CRITICAL] CVE-2010-3567 OpenJDK ICU Opentype layout engine crash (6963285)
CVE-2010-3567 OpenJDK ICU Opentype layout engine crash (6963285)
A crash in ICU Opentype layout engine was caused by a miscalculation in
character counts for right-to-left text causing out-of-bounds memory access.
This could be misused by remote attackers to potentially execute code in the
context of the user running the java process. (CVE-2010-3567)
The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHS
Bugzilla
CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)
bugzilla·2010-10-12·CVSS 10.0
CVE-2010-3553 [CRITICAL] CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)
CVE-2010-3553 OpenJDK Swing unsafe reflection usage (6622002)
The UIDefault.ProxyLazyValue class has unsafe reflection usage.
It did not properly check the permissions of the caller and allowed untrusted
callers to create objects via ProxyLazyValue
UIDefault.ProxyLazyValue.(CVE-2010-3553)
The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
Bugzilla
CVE-2010-3566 OpenJDK ICC Profile remote code execution (6963489)
bugzilla·2010-10-04·CVSS 10.0
CVE-2010-3566 [CRITICAL] CVE-2010-3566 OpenJDK ICC Profile remote code execution (6963489)
CVE-2010-3566 OpenJDK ICC Profile remote code execution (6963489)
ICC Profile Device Information Tag Remote Code Execution Vulnerability.
This issue (CVE-2010-3566) is not exploitable when using OpenJDK on Red Hat Enterprise Linux 5 and 6; however, the fix was added as a defense in depth patch.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0807 https://rhn.red
Bugzilla
CVE-2010-3568 OpenJDK Deserialization Race condition (6559775)
bugzilla·2010-10-04·CVSS 10.0
CVE-2010-3568 [CRITICAL] CVE-2010-3568 OpenJDK Deserialization Race condition (6559775)
CVE-2010-3568 OpenJDK Deserialization Race condition (6559775)
Race condition in the way objects were deserialized could allow an untrusted applet or application to misuse the privileges of the user running the applet or application. (CVE-2010-3568)
The CVSSv2 scored upstream is
cvss2=7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in fo
Bugzilla
CVE-2010-3557 OpenJDK Swing mutable static (6938813)
bugzilla·2010-10-04·CVSS 6.8
CVE-2010-3557 [MEDIUM] CVE-2010-3557 OpenJDK Swing mutable static (6938813)
CVE-2010-3557 OpenJDK Swing mutable static (6938813)
Flaws in the Swing library could allow an untrusted application to modify the
behavior and state of certain JDK classes. (CVE-2010-3557)
The CVSSv2 scored upstream is
cvss2=6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0770 https://rhn.redhat.com/errata/RHSA-2010-0770.html
---
This issue has been addressed in following products:
Extras for RHEL 3
Extras for RHEL 4
Extra
Bugzilla
CVE-2010-3564 OpenJDK kerberos vulnerability (6958060)
bugzilla·2010-10-04·CVSS 6.4
CVE-2010-3564 [MEDIUM] CVE-2010-3564 OpenJDK kerberos vulnerability (6958060)
CVE-2010-3564 OpenJDK kerberos vulnerability (6958060)
The Kerberos implementation improperly checked the sanity of AP-REQ requests,
which could cause a denial of service condition in the receiving Java Virtual
Machine. (CVE-2010-3564)
The CVSSv2 scored upstream is
cvss2=4.0/AV:N/AC:L/Au:S/C:N/I:N/A:P
Reference:
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0768 https://rhn.redhat.com/errata/RHSA-2010-0768.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2010:0865 https://rhn.redhat.com/errata/RHSA-2010-0865.html
http://secunia.com/advisories/39140http://www-01.ibm.com/support/docview.wss?uid=swg1PK97376http://www.securityfocus.com/bid/39051https://exchange.xforce.ibmcloud.com/vulnerabilities/57164http://secunia.com/advisories/39140http://www-01.ibm.com/support/docview.wss?uid=swg1PK97376http://www.securityfocus.com/bid/39051https://exchange.xforce.ibmcloud.com/vulnerabilities/57164
2010-04-01
Published