Skip to main content

PM05829: PORTLET PALETTE SECURITY VULNERABILITY


Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The search field within the Portlet Palette of IBM WebSphere
    Portal is vulnerable to Cross-Site Scripting (XSS).
    Authentication is required to exploit this vulnerability.
    

Local fix

Problem summary

  • security vulnerability
    

Problem conclusion

  • apply this fix
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM05829

  • Reported component name

    WEBSPHERE PORTA

  • Reported component ID

    5724E7600

  • Reported release

    60J

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2010-01-25

  • Closed date

    2011-09-06

  • Last modified date

    2011-09-06

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE PORTA

  • Fixed component ID

    5724E7600

Applicable component levels

  • R60J PSY

       UP

Rate this page:

(0 users)Average rating

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page:


(0 users)Average rating

Add comments

Document information

WebSphere Portal


Software version:
6.0.1.5


Reference #:
PM05829


Modified date:
2011-09-06

Translate my page

Content navigation