IBM WebSphere Application Server Cross Site Scripting Vulnerability
Publish date: 21 de julio de 2015
Gravedad: Crítico
Fecha recomendada: 21 de julio de 2015
Descripción
IBM WebSphere Application Server (WAS) contains a flaw that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the login page of the Integrated Solutions Console does not validate input to the 'username' parameter before returning it to users. This may allow a remote attacker to create a specially crafted request that would execute arbitrary script code in the 'Welcome [username]' message at the top of the dashboard page upon logging in.
Revelación de la información
Apply associated Trend Micro DPI Rules.
Soluciones
Trend Micro Deep Security DPI Rule Number: 1000552