Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere Application Server 跨站脚本攻击漏洞
Vulnerability Description
IBM WebSphere Application Server(WAS)是美国IBM公司的一款应用服务器产品。该产品是JavaEE和Web服务应用程序的平台,也是IBMWebSphere软件平台的基础。 IBM WebSphere Application Server存在跨站脚本漏洞源于其它应用程序使用的Apache MyFaces没有正确处理未加密的视图状态,远程攻击者可以利用包含修改序列化视图对象一些向量触发跨站脚本攻击(XSS),或执行任意表达式语言(EL)的语句。
CVSS Information
N/A
Vulnerability Type
N/A