IBM WebSphere Lombardi Edition Document Attachment Control Cross Site Scripting
Publish date: 21 de julio de 2015
Gravedad: Medio
Fecha recomendada: 21 de julio de 2015
Descripción
A cross-site scripting vulnerability exists in IBM WebSphere Lombardi Edition. The vulnerability is due to improper escaping of user input in certain coaches when document attachment control is enabled.
An attacker could exploit this vulnerability by enticing a user to follow a specially crafted link. Successful exploitation can allow an attacker to execute HTML or script code in the security context of the affected domain.
The vendor, IBM, has released an update to address this vulnerability:
http://www-01.ibm.com/support/docview.wss?uid=swg1IC79890
Revelación de la información
Apply associated Trend Micro DPI Rules.
Soluciones
Trend Micro Deep Security DPI Rule Number: 1000552
Trend Micro Deep Security DPI Rule Name: 1000552 - Generic Cross Site Scripting(XSS) Prevention