漏洞信息详情
IBM WebSphere Application Server管理控制台跨站脚本攻击漏洞
- CNNVD编号:CNNVD-201006-321
- 危害等级: 中危
- CVE编号: CVE-2010-2325
- 漏洞类型: 跨站脚本
- 发布时间: 2010-06-23
- 威胁类型: 远程
- 更新时间: 2010-06-23
- 厂 商: ibm
- 漏洞来源:
漏洞简介
IBM WebSphere Application Server是一个完善的、开放的Web应用服务器,它是IBM电子商务应用架构的核心。
z/OS上运行的IBM WebSphere Application Server (WAS)的管理控制台存在跨站脚本攻击(XSS)漏洞,远程攻击者可利用未明向量注入任意web脚本或HTML。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939
http://www-01.ibm.com/support/docview.wss?uid=swg1PM08892
http://www-01.ibm.com/support/docview.wss?uid=swg1PM10270
http://www-01.ibm.com/support/docview.wss?uid=swg1PM10684
http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829
http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830
参考网址
来源: VUPEN
名称: ADV-2010-1411
链接:http://www.vupen.com/english/advisories/2010/1411
来源: AIXAPAR
名称: PM15830
链接:http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830
来源: SECUNIA
名称: 40096
链接:http://secunia.com/advisories/40096
受影响实体
- Ibm Websphere_application_server:7.0.0.7
- Ibm Websphere_application_server:7.0.0.8
- Ibm Websphere_application_server:7.0.0.6
- Ibm Websphere_application_server:7.0.0.2
- Ibm Websphere_application_server:7.0
补丁
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for HP-UX
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for HP-UX
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Windows
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Windows
- 7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for ibm i
评论