« Back to list

CVE-2011-1357

Status: ModifiedMedium (4.3)—

Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2011-1357",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-08-11T22:55:00.863",
  "references": [
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg1IV01657",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/69040",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg1IV01657",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/69040",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en agentDetect.jsp en el web UI en IBM WebSphere Service Registry and Repository (WSRR) v6.3 anterior a v6.3.0.5, v7.0 anterior a v7.0.0.5, y v7.5 anterior a v7.5.0.1, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través header HTTP User-Agent"
    }
  ],
  "lastModified": "2026-06-16T23:29:12.710",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61668962-B744-40C2-8FFA-D6E48E841049"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92100CDC-DDA3-4AB3-829E-A936707EE6D4"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB11FDAF-3927-4609-920A-14449229A771"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB8DA020-7993-4C6D-A9AC-8E7D02375677"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:6.3.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "482DF55E-119B-4B70-93DA-D6193C10D023"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F0A1926-D9D5-45EF-AA33-185093A88074"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AE93FF0-3F54-48CC-B300-C061ACDC4639"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB1D1124-9E01-4196-B851-E9A23F766E3A"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4ADF778C-0771-42DF-A8D7-9F725D9584C2"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EE7B42E-5A06-4DEE-80BF-D7F886AE813F"
            },
            {
              "criteria": "cpe:2.3:a:ibm:websphere_service_registry_and_repository:7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F851A06-A356-41B5-B0AF-2C9EA362B08C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}