IBM Information for VU#560659
IBM WebSphere vulnerable to Cross-Site Scripting via passing of user input directly to default error page
- Vendor Information Help Date Notified: 20 Mar 2001
- Statement Date:
- Date Updated: 23 Aug 2001
IBM has fixed this vulnerability in WebSphere, and has a fix available to customers. The location of the fix is given in "III. Solution" of this Note. IBM does not support versions of WebSphere earlier than 3.02, so no fix is available for versions prior to 3.02.
We urge customers who employ affected versions of WebSphere to download and apply the fix described in this note as soon as possible to reduce their security exposure.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.