CVE-2017-1217
published 2017-07-05CVE-2017-1217: IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.08%
61.3th percentile
IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2017-7463 business-central: Reflected XSS in artifact upload error message
bugzilla·2017-04-06·CVSS 6.1
CVE-2017-7463 [MEDIUM] CVE-2017-7463 business-central: Reflected XSS in artifact upload error message
CVE-2017-7463 business-central: Reflected XSS in artifact upload error message
It was found that file upload functionality in business central allows javascript code to be included in the file that is executed via error message as it's being showed in HTML mode.
Upstream bug:
https://issues.jboss.org/browse/RHBPMS-4627
Discussion:
Acknowledgments:
Name: Chris Hebert, Vikas Pandey, Harold Schliesske, Ryan Stanley (Noblis)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.3
Via RHSA-2017:1218 https://access.redhat.com/errata/RHSA-2017:1218
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.3
Via RHSA-2017:1217 https://access.redhat.com/errata/RHSA-2017:1217
Bugzilla
CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
bugzilla·2017-04-06·CVSS 6.1
CVE-2017-2674 [MEDIUM] CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
CVE-2017-2674 business-central: Multiple stored XSS in task and process filters
It was found that Task Filter List in business central accepts HTML tags in the Name field. When creating a new task filtered list with crafted Name field and deleting it, HTML code is rendered.
Upstream bug:
https://issues.jboss.org/browse/RHBPMS-4625
Discussion:
Acknowledgments:
Name: Chris Hebert, Vikas Pandey, Harold Schliesske, Ryan Stanley (Noblis)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.3
Via RHSA-2017:1218 https://access.redhat.com/errata/RHSA-2017:1218
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.3
Via RHSA-2017:1217 https://access.redhat.com/errata/RHSA-2017:1217
http://www.ibm.com/support/docview.wss?uid=swg22004348http://www.securityfocus.com/bid/99350http://www.securitytracker.com/id/1038797https://exchange.xforce.ibmcloud.com/vulnerabilities/123857http://www.ibm.com/support/docview.wss?uid=swg22004348http://www.securityfocus.com/bid/99350http://www.securitytracker.com/id/1038797https://exchange.xforce.ibmcloud.com/vulnerabilities/123857
2017-07-05
Published