4.3

CVE-2008-0869

Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.

Data is provided by the National Vulnerability Database (NVD)
BeaWeblogic Server Version9.0
BeaWeblogic Server Version9.1
BeaWeblogic Server Version9.2
BeaWeblogic Workshop Version8.1 Updatesp2
BeaWeblogic Workshop Version8.1 Updatesp3
BeaWeblogic Workshop Version8.1 Updatesp4
BeaWeblogic Workshop Version8.1 Updatesp5
BeaWeblogic Workshop Version8.1 Updatesp6
Bea SystemsWeblogic Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.33% 0.528
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.