Vulnerability Name:

CVE-2001-0824 (CCN-6793)

Assigned:2001-07-02
Published:2001-07-02
Updated:2008-09-10
Summary:Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: BUGTRAQ
Type: UNKNOWN
20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability

Source: CCN
Type: BugTraq Mailing List, Mon Jul 02 2001 - 06:31:00 CDT
Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability

Source: MITRE
Type: CNA
CVE-2001-0824

Source: MITRE
Type: CNA
CVE-2001-0828

Source: MITRE
Type: CNA
CVE-2001-0829

Source: MITRE
Type: CNA
CVE-2001-1084

Source: MITRE
Type: CNA
CVE-2001-1121

Source: MITRE
Type: CNA
CVE-2001-1441

Source: CCN
Type: Apache Web site
Cross Site Scripting Info

Source: CCN
Type: Texas Metronet Web site
[ANNOUNCE] Tomcat 4.0 Beta 2

Source: CCN
Type: Resin Change Log
1.2.4 - April 11, 2001

Source: CCN
Type: US-CERT VU#270083
IBM VisualAge Professional vulnerable to Cross-Site Scripting via passing of user input directly to default error page

Source: CCN
Type: US-CERT VU#560659
IBM WebSphere vulnerable to Cross-Site Scripting via passing of user input directly to default error page

Source: CCN
Type: US-CERT VU#654643
Allaire JRun Java Application Server vulnerable to Cross-Site Scripting via passing of user input directly to default error page

Source: CCN
Type: US-CERT VU#672683
Apache Tomcat vulnerable to Cross-Site Scripting via passing of user input directly to default error page

Source: CCN
Type: US-CERT VU#981651
Caucho Technologies Resin vulnerable to Cross-Site Scripting via passing of user input directly to default error page

Source: CCN
Type: Macromedia Product Security Bulletin MPSB01-06
JRun 3.1, JRun 3.0, JRun 2.3.3: Cross-site scripting vulnerability (a.k.a. JavaScript code execution vulnerability)

Source: CCN
Type: Microsoft Security Bulletin MS00-060
Patch Available for 'IIS Cross-Site Scripting' Vulnerabilities

Source: CCN
Type: OSVDB ID: 15790
IBM WebSphere Application Server (WAS) Error Page XSS

Source: CCN
Type: OSVDB ID: 1890
Caucho Resin Java Servlet Error Page XSS

Source: CCN
Type: OSVDB ID: 1891
Allaire JRun Java Servlet Error Page XSS

Source: CCN
Type: OSVDB ID: 3880
VisualAge Java Servlet Error Page XSS

Source: CCN
Type: OSVDB ID: 829
IBM WebSphere Application Server (WAS) Java Servlet Error Page XSS

Source: CCN
Type: OSVDB ID: 844
Apache Tomcat Java Servlet Error Page XSS

Source: BID
Type: Exploit, Patch, Vendor Advisory
2969

Source: CCN
Type: BID-2969
IBM WebSphere Cross-Site Scripting Vulnerability

Source: CCN
Type: BID-2981
Caucho Technology Resin Cross-Site Scripting Vulnerability

Source: CCN
Type: BID-2982
Apache Tomcat Cross-Site Scripting Vulnerability

Source: CCN
Type: BID-2983
Allaire JRun Cross-Site Scripting Vulnerability

Source: XF
Type: UNKNOWN
java-servlet-crosssite-scripting(6793)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:websphere_application_server:3.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:3.5:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:macromedia:jrun:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:3.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:3.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:caucho:resin:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm websphere application server 3.0.2
    ibm websphere application server 3.5
    macromedia jrun 3.0
    ibm websphere application server 3.5.2
    ibm websphere application server 3.0.2
    caucho resin *