CVE-2014-6196

medium

Description

Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration, leading to improper construction of a response page by an application.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/98608

http://www-01.ibm.com/support/docview.wss?uid=swg21690018

http://www-01.ibm.com/support/docview.wss?uid=swg1LO82676

http://www-01.ibm.com/support/docview.wss?uid=swg1LO82675

http://www-01.ibm.com/support/docview.wss?uid=swg1LO82674

http://www-01.ibm.com/support/docview.wss?uid=swg1LO82673

http://www-01.ibm.com/support/docview.wss?uid=swg1LO82672

http://secunia.com/advisories/59546

Details

Source: Mitre, NVD

Published: 2014-11-26

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00452