← Back

CVE-2014-6196

nvd nist
Published: Nov 26, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration, leading to improper construction of a response page by an application.

Affected (13)

1 product
Web Experience Factory
Configuration A
13 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 6.1.5
Version 7.0.1.1
Version 7.0.1.2
Version 7.0.1.3
Version 7.0.1.4
Version 7.0.1
Version 8.0.0.1
Version 8.0.0.2
Version 8.0.0.3
Version 8.0.0
Version 8.0
Version 8.5.0.1
Version 8.5
Running on/withPlatform Versions
Ibm
Lotus Widget Factory
All versions
Ibm
Websphere Dashboard Framework
All versions

References (16)

Timeline

No history available yet.