IBM Information for VU#560659

IBM WebSphere vulnerable to Cross-Site Scripting via passing of user input directly to default error page



Vendor Statement

IBM has fixed this vulnerability in WebSphere, and has a fix available to customers. The location of the fix is given in "III. Solution" of this Note. IBM does not support versions of WebSphere earlier than 3.02, so no fix is available for versions prior to 3.02.

We urge customers who employ affected versions of WebSphere to download and apply the fix described in this note as soon as possible to reduce their security exposure.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.