IBM WEBi Cross-Site Scripting Vulnerability
Release date:
Updated on:
Affected Systems:
IBM Web Interface for Content Management (WEBi) 1.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2010-4476
IBM Web Interface (WEBi) is an interactive Web client that uses open standards and supports Web 2.0 and AJAX technologies.
WEBi has a security vulnerability. Attackers can exploit this vulnerability to execute cross-site scripts.
1) Some inputs are not properly filtered before being returned to the user, and can be used to execute arbitrary HTML and script code in the user's browser.
2) Vulnerabilities with unknown details.
<* Link: http://www.ibm.com/support/docview.wss? Uid = swg24029060
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/