Oval Definition:oval:org.cisecurity:def:1824
Revision Date:2017-03-10Version:6
Title:Cross-site scripting (XSS) vulnerability in MQ XR WebSockets Listener in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.5, and 8.0 before 8.0.0.2 – CVE-2015-0176
Description:IBM WebSphere MQ is vulnerable to reflected cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2015-0176
Platform(s):Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Vista
Product(s):IBM WebSphere MQ
Definition Synopsis
  • IBM WebSphere MQ is installed
  • AND Affected Versions
  • IBM WebSphere MQ 7.5
  • Check if IBM WebSphere MQ version is greater than or equal to 7.5.0.0
  • AND Check if IBM WebSphere MQ version is less than to 7.5.0.5
  • OR IBM WebSphere MQ 8.0
  • Check if IBM WebSphere MQ version is greater than or equal to 8.0.0.0
  • AND Check if IBM WebSphere MQ version is less than to 8.0.0.2
  • BACK