CVE Reference: CVE-2012-3293

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2012-3293

Description:
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a cross-frame scripting (XFS) issue.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/77179

CONFIRM
  http://www-01.ibm.com/support/docview.wss?uid=swg27022958
  http://www-01.ibm.com/support/docview.wss?uid=swg21606096

BID
  55149

AIXAPAR
  http://www-01.ibm.com/support/docview.wss?uid=swg1PM60839


Return to the previous page.