RULE(RULE ID:332974)

Rule General Information
Release Date: 2021-03-26
Rule Name: IBM WebSphere Application Server Cross Site Scripting Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A cross-site scripting vulnerability exists in IBM WebSphere Application Server (WAS). The flaw is due to lack of validation of the user supplied input data. The flaw may be exploited by malicious users to execute arbitrary HTML and script code on target user's web browser, within the context of a trusted web site. An attack targeting this vulnerability can result in the injection and execution of script code. If code execution is successful, the behaviour of the target will depend on the intention of the attacker. Unsuccessful attack attempts could either be unnoticed by the target user, or cause incorrect rendering of the affected web pages.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.