Vulnerability Name:

CVE-2015-7417 (CCN-107575)

Assigned:2015-09-29
Published:2016-01-19
Updated:2016-12-07
Summary:Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.
CVSS v3 Severity:5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
5.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2015-7417

Source: AIXAPAR
Type: UNKNOWN
PI49272

Source: CONFIRM
Type: Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21974520

Source: CCN
Type: IBM Security Bulletin 1974520 (WebSphere Application Server)
Cross-site scripting vulnerability in IBM WebSphere Application Server (CVE-2015-7417)

Source: CCN
Type: IBM Security Bulletin 1976218
Cross-site scripting vulnerability in Liberty for Java for IBM Bluemix (CVE-2015-7417)

Source: CCN
Type: IBM Security Bulletin 1976337
Cross-site scripting vulnerability in IBM WebSphere Application Server for Bluemix (CVE-2015-7417)

Source: CCN
Type: IBM Security Bulletin 1981197 (Security Key Lifecycle Manager)
Cross-site scripting vulnerability affects IBM Security Key Lifecycle Manager (CVE-2015-7417)

Source: CCN
Type: IBM Security Bulletin 1981914 (Control Center)
Multiple vulnerabilities in IBM WebSphere affect IBM Control Center (CVE-2016-0283, CVE-2015-7417).

Source: CCN
Type: IBM Security Bulletin 1987056 (Security Access Manager for Web)
A cross-site scripting vulnerability in IBM WebSphere Application Server affects IBM Security Access Manager Version 9 (CVE-2015-7417)

Source: CCN
Type: IBM Security Bulletin 1994916 (License Metric Tool)
A security vulnerabilities has been identified in WebSphere Liberty Profile shipped with IBM License Metric Tool v9 and IBM BigFix Inventory v9

Source: BID
Type: UNKNOWN
81738

Source: CCN
Type: BID-81738
IBM WebSphere Application Server CVE-2015-7417 Cross Site Scripting Vulnerability

Source: SECTRACK
Type: UNKNOWN
1034783

Source: XF
Type: UNKNOWN
ibm-websphere-cve20157417-xss(107575)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:websphere_application_server:7.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.25:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.27:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.29:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.31:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.33:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.35:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.37:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.39:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.10:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5.8:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:security_key_lifecycle_manager:2.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:license_metric_tool:9.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:control_center:6.0.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:control_center:6.1.0.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm websphere application server 7.0.0.0
    ibm websphere application server 7.0.0.1
    ibm websphere application server 7.0.0.2
    ibm websphere application server 7.0.0.3
    ibm websphere application server 7.0.0.4
    ibm websphere application server 7.0.0.5
    ibm websphere application server 7.0.0.7
    ibm websphere application server 7.0.0.9
    ibm websphere application server 7.0.0.11
    ibm websphere application server 7.0.0.13
    ibm websphere application server 7.0.0.15
    ibm websphere application server 7.0.0.17
    ibm websphere application server 7.0.0.19
    ibm websphere application server 7.0.0.21
    ibm websphere application server 7.0.0.23
    ibm websphere application server 7.0.0.25
    ibm websphere application server 7.0.0.27
    ibm websphere application server 7.0.0.29
    ibm websphere application server 7.0.0.31
    ibm websphere application server 7.0.0.33
    ibm websphere application server 7.0.0.35
    ibm websphere application server 7.0.0.37
    ibm websphere application server 7.0.0.39
    ibm websphere application server 8.0.0.0
    ibm websphere application server 8.0.0.1
    ibm websphere application server 8.0.0.2
    ibm websphere application server 8.0.0.3
    ibm websphere application server 8.0.0.4
    ibm websphere application server 8.0.0.5
    ibm websphere application server 8.0.0.6
    ibm websphere application server 8.0.0.7
    ibm websphere application server 8.0.0.8
    ibm websphere application server 8.0.0.9
    ibm websphere application server 8.0.0.10
    ibm websphere application server 8.0.0.11
    ibm websphere application server 8.5.0.0
    ibm websphere application server 8.5.0.1
    ibm websphere application server 8.5.0.2
    ibm websphere application server 8.5.5.0
    ibm websphere application server 8.5.5.1
    ibm websphere application server 8.5.5.2
    ibm websphere application server 8.5.5.3
    ibm websphere application server 8.5.5.4
    ibm websphere application server 8.5.5.5
    ibm websphere application server 8.5.5.6
    ibm websphere application server 8.5.5.7
    ibm websphere application server 8.5.5.8
    ibm websphere application server 7.0
    ibm websphere application server 8.0
    ibm websphere application server 8.5
    ibm websphere application server 8.5.5
    ibm security key lifecycle manager 2.5.0
    ibm license metric tool 9.2.0
    ibm control center 6.0.0.1
    ibm control center 6.1.0.0